Impact
The vulnerability exists because Nexus Repository 3 does not apply its existing SSRF protections to HTTP redirect targets returned by upstream proxy repository servers. As a result, an attacker‑controlled or compromised upstream server can return a redirect to an internal IP or cloud metadata endpoint, causing the repository to fetch that resource and serve it through the proxy repository as if it were legitimate repository content. This can expose sensitive information such as internal addresses or cloud IAM credentials to any user possessing read access to the proxy repository, including anonymous users if that access is enabled.
Affected Systems
Affected products are all releases of Sonatype Nexus Repository 3 from 3.0.0 up through 3.93.2 that have not applied the corrective release 3.94.0. The vulnerability applies to any installation that uses a proxy repository backed by an upstream server that is not fully trusted, regardless of the edition or deployment type.
Risk and Exploitability
The CVSS score of 4.9 indicates moderate severity, and the EPSS score of less than 1% indicates a low current probability of exploitation. The attack requires only read access to a proxy repository, a capability many environments expose. The exploit path is straightforward: the attacker induces a redirect to an attacker‑controlled internal URL, forces the repository to fetch that content, and delivers the response to the user. The vulnerability is not listed in the CISA KEV catalog, but the potential for leaking internal network data or cloud credentials warrants immediate attention.
OpenCVE Enrichment