Skip to content
COOEY

EXPOSURES › CVE-2020-10199

CVE-2020-10199

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-10199 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 75/100 rceexploited-in-wildunpatched

Sonatype Nexus Repository suffered a remote code execution vulnerability that was actively exploited in the wild.

An unspecified vulnerability in Sonatype Nexus Repository allowed remote code execution, and it was listed in CISA's KEV catalog as actively exploited. DIB organizations must ensure their software supply chain and repository tools are patched against known, exploited vulnerabilities to prevent attackers from executing arbitrary code on their infrastructure.

Shame score — The vulnerability was actively exploited in the wild and included in CISA's KEV catalog, indicating a severe, avoidable failure to patch a known, exploited flaw.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Sonatype Nexus Repository contains an unspecified vulnerability that allows for remote code execution.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.60
Remote code execution in a widely used repository manager is a critical flaw with severe fallout, though the provided source is purely factual and lacks commentary on Sonatype's response or the broade
cooey ↗ severe-fallout +0.00
neutral
"Sonatype Nexus Repository contains an unspecified vulnerability that allows for remote code execution."
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.