Impact
Nexus Repository Manager 3 has a flaw in its component upload API that bypasses the intended write‑permission check. A user who only has read or browse privileges on a Swift, Terraform, or Conda hosted repository can inject arbitrary artifacts into the Authorization Bypass (CWE‑862), allowing an attacker to tamper with the contents of a repository, potentially distributing malicious or tampered code to downstream consumers. The integrity of the managed packages is compromised, and supply‑chain attacks become possible if attackers control the upload process.
Affected Systems
The vulnerability affects Sonatype Nexus Repository Manager 3, specifically versions ranging from 3.88.0 through 3.93.2 as enumerated in the CPE list. These versions build attack surface.
Risk and Exploitability
The CVSS score of 8.2 marks the flaw as a high‑severity issue. The EPSS score of less than 1% indicates that the likelihood of real‑world exploitation remains low at present, and the vulnerability is not currently catalogued in CISA’s KEV list. Still, the attack vector is straightforward: an authenticated HTTP request to the upload endpoint is sufficient, requiring only read or browse rights that are commonly granted. Once exploited, the attacker can place any artifact into the repository, subverting downstream builds or deployments.
OpenCVE Enrichment