Impact
An authenticated user with the nx-licensing-create privilege can upload a specially crafted license file that triggers Java object deserialization by the Nexus process. This flaw allows the attacker to execute arbitrary operating system commands as the Nexus user, effectively compromising the host. The vulnerability is a classic example of insecure deserialization (CWE-502) and results in a high‑impact remote code execution scenario where the attacker gains full system control over the running Nexus instance.
Affected Systems
Sonatype Nexus Repository 3 releases before 3.92.0 are vulnerable. This includes versions 3.0.0 through 3.91.1 as enumerated in the supplied CPE list, covering a wide range of early and intermediate releases.
Risk and Exploitability
The CVSS score of 8.6 indicates a high severity. However, the EPSS score of less than 1% suggests that the likelihood of exploitation is low at this time, and the vulnerability is not currently listed in the CISA KEV catalog. The likely attack vector requires legitimate authentication with the nx-licensing-create privilege, typically performed by administrators or automated processes that manage Nexus licenses. Once the privilege is established, an attacker can upload a malicious license file to trigger the deserialization flaw and execute commands as the Nexus process user.
OpenCVE Enrichment