Server-Side Request Forgery in Sonatype Nexus Repository
CVE-2025-9868
8.7HIGH
What is CVE-2025-9868?
A Server-Side Request Forgery (SSRF) vulnerability exists in the Remote Browser Plugin of Sonatype Nexus Repository. This issue allows unauthenticated remote attackers to craft HTTP requests that can exfiltrate sensitive proxy repository credentials.
Affected Version(s)
Nexus Repository 2.0.0 <= 2.15.2