EXPOSURES › CVE-2020-10199
CVE-2020-10199
HIGH ⌖ ON CISA KEV · EXPLOITEDSonatype Nexus Repository suffered a remote code execution vulnerability that was actively exploited in the wild.
An unspecified vulnerability in Sonatype Nexus Repository allowed remote code execution, and it was listed in CISA's KEV catalog as actively exploited. DIB organizations must ensure their software supply chain and repository tools are patched against known, exploited vulnerabilities to prevent attackers from executing arbitrary code on their infrastructure.
Shame score — The vulnerability was actively exploited in the wild and included in CISA's KEV catalog, indicating a severe, avoidable failure to patch a known, exploited flaw.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Sonatype Nexus Repository contains an unspecified vulnerability that allows for remote code execution.
"Sonatype Nexus Repository contains an unspecified vulnerability that allows for remote code execution."