在受影响的 Nexus Repository 3 版本中,脚本执行端点(POST /service/rest/v1/script/{name}/run)未验证脚本执行是否已被管理层面禁用。即使管理员将配置项 设置为 ,拥有“脚本执行”权限的账户仍可以继续运行之前创建的脚本,从而破坏了该配置项能够完全阻止脚本执行的预期效果。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Sonatype | Nexus Repository 3 | 3.21.2< 3.96.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Sonatype | Nexus Repository 3 | 3.21.2 ~ 3.96.0 |
cpe:2.3:a:sonatype:nexus_repository_manager:3.21.2:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-77125 | 7.1 HIGH | Nexus Repository 3 - Incorrect Authorization on Blobstore Group Endpoints |
| CVE-2026-77123 | 6.0 MEDIUM | Nexus Repository 3 - Webhook Secret Disclosure via Capability Read API |
| CVE-2026-77121 | 5.3 MEDIUM | Nexus Repository 3 - Denial of Service via Unbounded Maven POM Metadata Fields |
| CVE-2026-77122 | 5.3 MEDIUM | Nexus Repository 3 - Incorrect Authorization Allows Disclosure of Member Repository Metada |
No comments yet