Impact
The root issue is a Server‑Side Request Forgery vulnerability in the SSL Certificate Retrieval endpoint of Nexus Repository 3. The flaw allows a user who has the nexus:ssl-truststore:read permission to instruct the server to establish outbound connections to arbitrary network addresses. A malicious user could therefore discover internal hosts, exfiltrate data, or use the node as a proxy for further attacks. The damage scope is confined to the internal network and the permissions of the authenticated user, but it can still facilitate sensitive data disclosure or lateral movement.
Affected Systems
Sonatype Nexus Repository editions 3.0.0 up to 3.93.2 are affected. All versions released between these endpoints, inclusive, are listed in the provided CPE data within the CVE entry.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score is below 1 %, implying that the vulnerability is unlikely to be actively exploited in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires the target to possess the nexus:ssl-truststore:read role, which is typically limited to users with repository maintenance privileges. The attack vector is thus limited to legitimate users with read access to the SSL trust store, making it an authenticated SSRF scenario rather than a fully unauthenticated remote exploit.
OpenCVE Enrichment