Impact
Sonatype Nexus Repository Manager 3 does not properly filter internal configuration keys in user‐supplied task properties when creating or updating a scheduled task through the administrative UI. A user with permission to create at least one scheduled task type can supply a crafted property value that causes the system to overwrite the configuration of an existing task instead of creating a new one. This flaw enables an attacker to alter or disable critical automated processes, potentially disrupting build pipelines or repository maintenance tasks. The vulnerability is a classic input validation weakness, identified as CWE‑915.
Affected Systems
The flaw applies to Sonatype Nexus Repository Manager 3 versions 3.91.0 through 3.94.1. Any deployment of these releases without the latest patches is susceptible.
Risk and Exploitability
The CVSS score is 5.3, indicating moderate severity. The EPSS score is not available, so the estimated likelihood of exploitation is unknown. The vulnerability is not listed in the CISA KEV catalog. Attackers need authenticated access with the privilege to create scheduled tasks; thus the vector is likely internal or privileged. Once compromised, the attacker can modify existing tasks, leading to denial of service or incorrect repository behavior.
OpenCVE Enrichment