Impact
A stored cross‑site scripting flaw allows a user with the nexus:blobstores:create or nexus:blobstores:update permission to embed malicious script into a blob store name. When another user opens the system health‑check status page, the script is rendered and executed in the victim's browser, permitting actions such as cookie theft, session hijacking, or arbitrary JavaScript execution within the context of the Nexus Repository UI. This represents a moderate‑to‑high impact to confidentiality, integrity, and availability of the application user experience, but does not allow direct system compromise beyond the browser.
Affected Systems
The vulnerability affects Sonatype Nexus Repository 3 versions up to and including 3.94.1. The issue was fixed in version 3.95.0, so any instance running an earlier release is susceptible.
Risk and Exploitability
The CVSS score of 6.3 indicates a moderate risk, and the attack requires the attacker to possess blob store creation or update privileges and rely on another user visiting the health‑check page. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting lower exploitation prevalence. Nonetheless, the requirement of authenticated privileged access and active user interaction makes exploitation plausible in a compromised environment.
OpenCVE Enrichment