CVE-2020-15871

Executive Summary

Sonatype Nexus Repository Manager OSS/Pro versions prior to 3.25.1 are vulnerable to remote code execution via an unvalidated input flaw, allowing attackers to send crafted requests that execute arbitrary code on the host. This can compromise the entire system and its hosted artifacts. The vulnerability is not currently listed in the CISA KEV database.


Authoritative CVE Metadata - CVSS Base Score: 8.8 (HIGH) - Published: 2020-07-31T20:15:12.737 - Last Modified: 2026-09-22T18:11:49.490

Original Description: Sonatype Nexus Repository Manager OSS/Pro version before 3.25.1 allows Remote Code Execution.

"Our kindness may be the most persuasive argument for that which we believe."

— Gordon Hinckley
Source: NVD