| [Japanese] | |
JVNDB-2026-000015 | |
Sonatype Nexus Repository vulnerable to server-side request forgery | |
| Overview | |
Nexus Repository provided by Sonatype contains the following vulnerability. | |
| CVSS Severity (What is CVSS?) | |
|
CVSS V3 Severity:
Base Metrics 7.6 (High) [IPA Score]
| |
| Affected Products | |
|
| |
Sonatype Inc. | |
|
| |
| Impact | |
The remote storage URL can be configured to point to some network destination, such as cloud meta data services or inside the local networks, which are not expected to be accessed from the product. | |
| Solution | |
[Update and Configure the Software Appropriately] | |
| Vendor Information | |
Sonatype Inc. | |
| CWE (What is CWE?) | |
| |
| CVE (What is CVE?) | |
|
| |
| References | |
| |
| Revision History | |
|
| Date Public | 2026/02/02 |
| Date First Published | 2026/02/02 |
| Date Last Updated | 2026/02/02 |


