216.73.216.36

CVE-2025-9868

· Published 08/10/2025 18:15 · Modified 08/10/2025 19:38

Labels: CVE-2025-9868 103e4ec9-0a87-450b-af77-479448ddef112025-10-08CVE-2025-9868CWE-918

Essential information

Published
08/10/2025 18:15
Modified
08/10/2025 19:38
Author
Creator
CVSS
8.7 HIGH (v3) 8.7 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Server-Side Request Forgery (SSRF) in the Remote Browser Plugin in Sonatype Nexus Repository 2.x up to and including 2.15.2 allows unauthenticated remote attackers to exfiltrate proxy repository credentials via crafted HTTP requests.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
103e4ec9-0a87-450b-af77-479448ddef11
NVD
View on NVD

Affected products (CPE)

ProductCPE
sontatype / nexus repository cpe:2.3:a:sontatype:nexus_repository:2.15.2:*:*:*:*:*:*:*
sontatype / nexus repository cpe:2.3:a:sontatype:nexus_repository:2.0:*:*:*:*:*:*:*

References