Java Expression Language Injection Vulnerability in Sonatype Nexus Repository Manager
CVE-2018-16621
7.2HIGH
What is CVE-2018-16621?
A vulnerability exists in Sonatype Nexus Repository Manager that allows for Java Expression Language Injection. This flaw can enable attackers to manipulate and execute unexpected Java expressions, potentially leading to unauthorized actions within the repository system. It affects versions prior to 3.14, emphasizing the need for users to apply available updates and mitigate risks to their environments.