Sonatype Nexus Repository
cpe:2.3:a:sonatype:nexus_repository_manager:*:*:*:*:*:*:*, +1 more
- >= 3.0.0, <= 3.90.2
A reflected cross-site scripting vulnerability has been identified in Sonatype Nexus Repository versions 3.0.0 prior to 3.90.2. This vulnerability allows unauthenticated remote attackers to execute arbitrary JavaScript in the context of a victim's browser by sending a specially crafted URL. Exploitation of this vulnerability requires user interaction, as the victim must click on the malicious link.
Exploitation of this vulnerability allows for reflected cross-site scripting, where an attacker can inject and execute malicious JavaScript in the victim's browser.
Users are advised to upgrade to Sonatype Nexus Repository version 3.91.0 or later. The latest version can be downloaded from the Sonatype Nexus Repository Downloads page.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.