CVE-2020-10199

CVE Published 2020-04-01
Related CWE(s) CWE-917: Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
Related Vendor(s) sonatype
Related Product(s) nexus
Exploitation Reported (CISA KEV) 2021-11-03
CVSS 3 Base Score 8.8 (HIGH)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector NETWORK

Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

References