Description
An authenticated user with the nx-licensing-create privilege can upload a specially crafted license file to execute arbitrary operating system commands as the Nexus process user in Sonatype Nexus Repository 3 versions before 3.92.0.
Problem types
CWE-502 Deserialization of Untrusted Data
Product status
3.0.0 (semver) before 3.92.0
Credits
Rahul Maini with Hacktron AI
References
help.sonatype.com/...us-repository-3-92-0-release-notes.html
support.sonatype.com/hc/en-us/articles/52335766035603