Impact
When a user’s Nexus Repository 3 account is deleted, deactivated, or its password altered, the active login session is not immediately terminated. The session continues to operate with the permissions that existed at the time of account modification, allowing that user to read, modify, or delete repository contents as if the account were still active. This flaw is a CWE-613 weakness in which authentication information is retained and leads to persistence of unauthorized access.
Affected Systems
All supported Sonatype Nexus Repository 3 versions listed in the CPE set are affected. The product is Sonatype Nexus Repository 3; the vulnerable versions encompass the entire range of 3.x releases, from 3.0.0 up through the most recent 3.94.1. Administrators should verify that their deployed instance falls within this range and that no lower‑version instance remains in use.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.7, indicating high severity. The EPSS score is not available, and the flaw is not currently listed in CISA’s KEV catalog. Attackers who have or can obtain a session before or during a deletion/deactivation event can exploit the flaw. The attack requires administrative or account‑management permissions to trigger the deletion or deactivation, or the ability to change a password; once triggered, the attacker does not need additional privileges to use the existing session. The exploitation is straightforward and could result in significant damage to repository integrity and confidentiality.
OpenCVE Enrichment