CVE-2020-11753
Executive Summary
CVE-2020-11753 affects Sonatype Nexus Repository Manager 3.21.1 and 3.22.0, allowing privileged users to create, modify, and execute scripting tasks via non‑UI methods. In 3.22.0 scripting is disabled by default, mitigating exploitation. The vulnerability could enable arbitrary code execution or privilege escalation within the repository environment.
Authoritative CVE Metadata - CVSS Base Score: 8.8 (HIGH) - Published: 2020-04-20T19:15:11.557 - Last Modified: 2026-09-22T18:13:24.090
Original Description: An issue was discovered in Sonatype Nexus Repository Manager in versions 3.21.1 and 3.22.0. It is possible for a user with appropriate privileges to create, modify, and execute scripting tasks without use of the UI or API. NOTE: in 3.22.0, scripting is disabled by default (making this not exploitable).
"Great talent finds happiness in execution."
— Johann Wolfgang von Goethe