Impact
An authorization flaw in the GET /service/rest/v1/repositories/{repositoryName} endpoint of Sonatype Nexus Repository 3 allows a user with read or browse permission on a group repository to retrieve metadata for member repositories that the user does not directly own. The disclosed metadata can include the remote URL for proxy repositories, potentially revealing internal hostnames, and the flaw may also affect anonymous users if their role has been granted this permission.
Affected Systems
All Sonatype Nexus Repository 3 installations from version 3.38.0 up through 3.95.3 are impacted. The vulnerability applies to group repositories whose members are proxy, hosted, or other repository types. The specific installation profile, such as anonymous user role configuration, determines whether the anonymous user can exploit the flaw.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be network-based; an attacker must be able to reach the REST API and possess at least read or browse access to a group repository. If anonymous users are granted such permissions, the flaw could be exploited without authentication. The exposure includes sensitive repository metadata, but does not directly lead to code execution or full system compromise.
OpenCVE Enrichment