Sonatype Nexus Repository Manager before 3.14 allows Java Expression Language Injection.
The product constructs all or part of an expression language (EL) statement in a framework such as a Java Server Page (JSP) using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended EL statement before it is executed.
Link | Tags |
---|---|
https://support.sonatype.com/hc/en-us/articles/360010789153-CVE-2018-16621-Nexus-Repository-Manager-Java-Injection-October-17-2018 | patch vendor advisory |
https://securitylab.github.com/advisories/GHSL-2020-015-nxrm-sonatype | third party advisory exploit |