Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w968-mx3g-7grf

Опубликовано: 08 окт. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.7

Описание

Server-Side Request Forgery (SSRF) in the Remote Browser Plugin in Sonatype Nexus Repository 2.x up to and including 2.15.2 allows unauthenticated remote attackers to exfiltrate proxy repository credentials via crafted HTTP requests.

Server-Side Request Forgery (SSRF) in the Remote Browser Plugin in Sonatype Nexus Repository 2.x up to and including 2.15.2 allows unauthenticated remote attackers to exfiltrate proxy repository credentials via crafted HTTP requests.

EPSS

Процентиль: 38%
0.00166
Низкий

8.7 High

CVSS4

Дефекты

CWE-918

Связанные уязвимости

nvd
7 дней назад

Server-Side Request Forgery (SSRF) in the Remote Browser Plugin in Sonatype Nexus Repository 2.x up to and including 2.15.2 allows unauthenticated remote attackers to exfiltrate proxy repository credentials via crafted HTTP requests.

EPSS

Процентиль: 38%
0.00166
Низкий

8.7 High

CVSS4

Дефекты

CWE-918