Impact
An incorrect authorization check in Nexus Repository 3 enables a user with delegated repository‑admin privileges for a specific repository format to create a repository of a different, unauthorized format. The vulnerability arises because the authorization was evaluated against one request field, while the repository format used by the system was set by a separate attacker‑controlled field, leading to a mis‑authorization of the creation action. This flaw permits the attacker to establish repositories outside the constraints of their granted permissions, potentially exposing configuration settings or existing artifacts to unintended users.
Affected Systems
Sonatype Nexus Repository 3 Community Edition and Professional Edition versions from 3.0.0 through 3.94.x are affected. The vulnerability does not apply to anonymous users, as they cannot hold repository‑admin privileges by default.
Risk and Exploitability
The CVSS score of 8.2 indicates a high severity impact. Attackers require a valid account with delegated repository‑admin rights to exploit the flaw, so the attack surface is limited to authenticated users. No EPSS score is available, and the flaw is not listed in CISA KEV; however, because the issue permits creation of unauthorized repository formats, it carries a substantial risk of privilege escalation and potential lateral movement within the repository environment. Monitoring of repository creation activities and limiting delegated admin privileges can reduce the likelihood of successful exploitation.
OpenCVE Enrichment