CVE-2020-10199
Sonatype Nexus Repository Remote Code Execution Vulnerability
- Published
- Apr 1, 2020
- Updated
- Oct 21, 2025
- Assigning CNA
- mitre
- Evidence observed
- Apr 17, 2020
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HHigh · next 30 days
- Percentile
- 99.9%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
CISA Known Exploited
This CVE appears in the CISA Known Exploited Vulnerabilities catalog.
Summary
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
Sources
10- CVE-2020-10199Exploit
Proof-of-concept and technical walkthrough demonstrating remote code execution in Sonatype Nexus, including EL injection debugging, BCEL payload construction, and reverse shell establishment.
- CVE-2020-10199Exploit
PoC exploit collection for Nexus Repository Manager 3 vulnerabilities (CVE-2020-10199, CVE-2020-10204, CVE-2020-11444) enabling remote code execution and privilege escalation via HTTP endpoints.
CVE-2020-10199、CVE-2020-10204漏洞一键检测工具,图形化界面。CVE-2020-10199 and CVE-2020-10204 Vul Tool with GUI.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.