CVE-2020-10199

HIGH(8.8)KEVLikely Exploited

Sonatype Nexus Repository Remote Code Execution Vulnerability

Description

CVE-2020-10199 is a high-severity Expression Language (EL) injection vulnerability in Sonatype Nexus Repository Manager. Versions prior to 3.21.2 allow authenticated attackers to inject and execute arbitrary Java Expression Language statements, leading to remote code execution on the underlying server. CISA has added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation in the wild. With an EPSS score of 94.38% (99.97th percentile), CVE-2020-10199 has a near-certain probability of exploitation, making immediate patching essential for any organization running an affected Sonatype Nexus Repository instance.

KEV Information

Vendor
Sonatype
Product
Nexus Repository
Date Added
November 3, 2021
Due Date
May 3, 2022
Required Action
Apply updates per vendor instructions.

CVSS Score

Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HOpen in Calculator
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
5.9

CWEs

Affected Products

VendorProductVersion
sonatypenexus< 3.21.2

Multiple CVSS Assessments

Source: [email protected](Primary)
8.8
HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0(Secondary)
8.8
HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

References

Weakness Type

CWE-917: Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')

Expression Language Injection occurs when user-controlled input is embedded into EL statements without proper sanitization. In the case of Sonatype Nexus Repository Manager, this weakness allows authenticated users to craft malicious EL expressions that are evaluated by the server, granting the ability to execute arbitrary code and access sensitive internal application data.

Learn more: CWE-917 — Expression Language Injection

Impact Analysis

CVE-2020-10199 carries a CVSS 3.1 score of 8.8 (HIGH), reflecting a serious threat to organizations using Sonatype Nexus Repository Manager. The vulnerability is remotely exploitable over the network with low attack complexity, requiring only low-privilege authentication and no user interaction. Successful exploitation results in high impact across confidentiality, integrity, and availability, meaning an attacker can read sensitive data, modify repository contents, and disrupt service availability. The EPSS score of 94.38% places this vulnerability in the 99.97th percentile, indicating near-certain active exploitation. Organizations relying on Nexus Repository for artifact management face critical supply chain risk if this vulnerability remains unpatched, as compromised repositories can serve as distribution points for malicious artifacts.

Exploit Maturity

CVE-2020-10199 has a highly mature exploit landscape. Public exploit code is available via Packet Storm Security and additional exploit material has been published at Packet Storm Security, significantly lowering the barrier for attackers. CISA has confirmed active exploitation in the wild by including this vulnerability in the Known Exploited Vulnerabilities catalog, with a remediation deadline of 2022-05-03. The EPSS score of 94.38% indicates near-certain exploitation activity, making this one of the most actively targeted vulnerabilities in the Nexus Repository ecosystem.

Remediation

  1. Apply updates immediately as required by CISA KEV: upgrade Sonatype Nexus Repository Manager to version 3.21.2 or later, which addresses the EL injection vulnerability.
  2. Verify that all Nexus Repository instances running versions prior to 3.21.2 have been identified and updated. Review the vendor advisory at the Sonatype support portal for specific upgrade instructions.
  3. If immediate patching is not feasible, restrict network access to the Nexus Repository Manager administrative interface using firewall rules and network segmentation, and enforce strict authentication controls to limit who can access the application.
  4. Monitor Nexus Repository logs for indicators of compromise, including unusual API calls, unexpected expression evaluation errors, and unauthorized repository modifications. Review access logs for suspicious authenticated sessions.
  5. As a long-term measure, disable expression language evaluation where not required, sanitize all user inputs before incorporating them into server-side expressions, and implement defense-in-depth by restricting accessible classes and methods within the application runtime.

Technical Details

CVE-2020-10199 exploits a Java Expression Language (EL) injection flaw in Sonatype Nexus Repository Manager versions prior to 3.21.2. The vulnerability arises because user-controlled input is incorporated into EL statements without proper neutralization of special elements, allowing an authenticated attacker to inject malicious expressions that the server evaluates. The CVSS vector string (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) confirms that exploitation is network-based with low complexity, requires only low-level privileges, and results in complete compromise of confidentiality, integrity, and availability within the vulnerable component. This is classified as the first of two related EL injection issues discovered in the product, indicating a systemic pattern of insufficient input sanitization in the expression evaluation pipeline.

Frequently Asked Questions

Is CVE-2020-10199 being actively exploited?

Yes. CVE-2020-10199 is listed in the CISA Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. The EPSS score of 94.38% (99.97th percentile) indicates near-certain exploitation probability, and multiple public exploits are available.

What products are affected by CVE-2020-10199?

CVE-2020-10199 affects Sonatype Nexus Repository Manager versions prior to 3.21.2. Organizations using any version below 3.21.2 should treat this as an urgent patching priority.

How do I fix CVE-2020-10199?

Upgrade Sonatype Nexus Repository Manager to version 3.21.2 or later. If immediate patching is not possible, restrict network access to the Nexus administrative interface and enforce strict authentication policies to limit exposure.

How severe is CVE-2020-10199?

CVE-2020-10199 has a CVSS 3.1 score of 8.8 (HIGH) and an EPSS score in the 99.97th percentile. The vulnerability allows authenticated remote code execution, making it a critical threat that requires immediate remediation.

CVSS Score

8.8
HIGH(8.8)

EPSS Score

EPSS Score99.06%
EPSS Percentile99.9%

Dates

PublishedApril 1, 2020
Last ModifiedJune 17, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.