Impact
Affected component is Sonatype Nexus Repository Manager. The vulnerability arises from insufficient entropy used when generating format‑specific API keys (NuGet, Docker, npm). Because generated keys can be predicted, an attacker who guess a valid key and authenticate as the targeted user, gaining unauthorized access to repository operations. The flaw is a CWE‑331 (Insufficient Entropy).
Affected Systems
All supported Nexus Repository Manager releases that provide format‑specific API key realms are impacted, covering the extensive range of v3.x versions listed in the CPE data. The vulnerability applies only when the format‑specific API key realm is enabled and the target user possesses an active API key. Users running any of those versions without disabling these realms or without applying the fix are potentially vulnerable.
Risk and Exploitability
The CVSS score of 8.7 marks it as high severity, but the EPSS of <1% indicates a very low current exploitation probability. It is not listed in the CISA KEV catalog. Remote exploitation requires network access to the Nexus server and knowledge of which API key realm to target. An attacker can exploit the weak randomness to generate or brute‑force a valid key, impersonate the user, and perform any repository operation allowed for that user.
OpenCVE Enrichment