CVE-2026-3438

⚪ Do wiadomości

Luka XSS w Sonatype Nexus Repository pozwala na wykonanie JavaScript w przeglądarce ofiary.

CVSS
6.1
EPSS
0.5%
Exploit
none
Vendor
sonatype
Opis źródłowy (NVD)

A reflected cross-site scripting vulnerability exists in Sonatype Nexus Repository versions 3.0.0 through 3.90.2 that allows unauthenticated remote attackers to execute arbitrary JavaScript in a victim's browser through a specially crafted URL. Exploitation requires user interaction.

xss Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS6.1
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.5%
Opublikowano (NVD)2026-04-08 23:16:59 UTC
Ostatnia modyfikacja (NVD)2026-09-18 15:38:49 UTC
Referencje