Sonatype nexus repository manager是美国Sonatype公司开源的一个软件仓库管理平台。 Sonatype Nexus Repository Manager存在服务端请求伪造漏洞,该漏洞源于未对代理仓库上游服务器返回的HTTP重定向目标应用现有的服务器端请求伪造(SSRF)保护,可能导致具有代理仓库读取权限的用户(包括匿名用户)接收来自内部网络地址或云元数据端点的响应作为仓库内容,从而暴露敏感信息如云IAM凭据。以下版本受到影响:3.0.0版本至3.94.0之前版本。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Sonatype | Nexus Repository 3 | 3.0.0< 3.94.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Sonatype | Nexus Repository 3 | 3.0.0 ~ 3.94.0 |
cpe:2.3:a:sonatype:nexus_repository_manager:3.0.0:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-11403 | Nexus Repository Manager - Insufficient Entropy in Format-Specific API Key Generation | |
| CVE-2026-7494 | Nexus Repository - SSRF in SSL Certificate Retrieval | |
| CVE-2026-14504 | Nexus Repository 3 - Authorization Bypass in Component Upload API | |
| CVE-2026-14645 | Nexus Repository 3 - Server-Side Request Forgery (SSRF) via Webhook: Global Capability |
No comments yet