Impact
The vulnerability allows a user with Capability Administration permission to configure a webhook that causes the Nexus Repository server to perform Server‑Side Request Forgery to arbitrary network locations, potentially exfiltrating data or enabling further attacks. This compromise of confidentiality and integrity of internal resources is due to insufficient validation of the webhook destination, classified as CWE‑918. Additionally, because the permission is granted by role assignment independent of authentication status, an unauthenticated user could also trigger this behavior if the anonymous role has been granted the permission.
Affected Systems
All Sonatype Nexus Repository 3 instances are potentially affected, including the wide range of releases listed in the CPE identifiers—from 3.0.0 up through the latest 3.93.2 series. Any deployment that still supports the "Webhook: Global" capability is at risk, regardless of the Capability Administration permission.
Risk and Exploitability
The CVSS score of 5.1 denotes moderate severity, and the EPSS score of less than 1% indicates a very low likelihood of current exploitation in the wild. The vulnerability is not listed in CISA KEV, suggesting no public exploit has been observed. Attackers would need to obtain or leverage Capability Administration rights (including possibly unauthenticated users if the anonymous role includes the permission), but this privilege can be limited or revoked to reduce risk. Due to the moderate score and low exploitation probability, risk to environments that harden permissions or are patch‑updated remains relatively contained.
OpenCVE Enrichment