Vulnerabilities
Vulnerable Software
An authenticated administrator who configures or tests LDAP connectivity in Sonatype Nexus Repository Manager versions 3.0.0 through 3.91.1 may be able to initiate unintended server-side connections when interacting with a malicious LDAP server.
CVSS Score
5.1
EPSS Score
0.003
Published
2026-05-11
A vulnerability in the task management component of Sonatype Nexus Repository versions 3.22.1 through 3.90.2 allows an authenticated attacker with task creation permissions to execute arbitrary code, bypassing the nexus.scripts.allowCreation security control.
CVSS Score
9.4
EPSS Score
0.006
Published
2026-04-08
A reflected cross-site scripting vulnerability exists in Sonatype Nexus Repository versions 3.0.0 through 3.90.2 that allows unauthenticated remote attackers to execute arbitrary JavaScript in a victim's browser through a specially crafted URL. Exploitation requires user interaction.
CVSS Score
5.1
EPSS Score
0.004
Published
2026-04-08


Contact Us

Shodan ® - All rights reserved