CVE-2020-10199 is a critical remote code execution vulnerability in Sonatype Nexus Repository Manager version 3.20.1. The vulnerability is due to the failure to apply the stripJavaEL() mitigation in the org.sonatype.nexus.validation.ConstraintViolationFactory, allowing user-controlled data to be evaluated as Java Expression Language (EL). This flaw is exploitable by any authenticated user, regardless of privilege, via endpoints for creating or updating GoLang group repositories. The vulnerable code path is in AbstractGroupRepositoriesApiResource and its subclass GolangGroupRepositoriesApiResource, where authorization checks are performed after the vulnerable bean validation, enabling exploitation before proper authorization is enforced.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This repository contains a single Metasploit module targeting a post-authentication Java Expression Language (EL) injection vulnerability (CVE-2020-10199) in Sonatype Nexus Repository Manager versions up to and including 3.21.1. The exploit requires valid credentials (any user) and leverages the /service/rest/beta/repositories/go/group API endpoint to inject a malicious EL expression, resulting in arbitrary command execution as the 'nexus' user. The module uses Metasploit's command stager to deliver a payload (default: linux/x64/meterpreter_reverse_tcp), providing the attacker with a reverse shell or Meterpreter session. The exploit checks the target's version by inspecting the Server header on the root path and authenticates via the /service/rapture/session endpoint. The code is well-structured, leverages Metasploit's HttpClient and CmdStager mixins, and is considered weaponized due to its integration with the Metasploit framework and support for customizable payloads.
This repository is a comprehensive exploit library (exphub) containing operational exploit scripts for a wide range of high-profile vulnerabilities affecting popular enterprise software. The structure is organized by product (e.g., drupal/, f5/, fastjson/, jboss/, nexus/, ofbiz/, shiro/, solr/, spring/, struts2/, tomcat/, weblogic/), with each directory containing Python or Java scripts for specific CVEs. The scripts are primarily remote code execution (RCE) exploits, but also include file read, webshell upload, SSRF, and administrative bypasses. Many scripts provide interactive shells or allow arbitrary command execution, and some require authentication. The repository includes both proof-of-concept (POC) and full exploit scripts, with detailed usage instructions embedded in the code and readme files. The attack vector is predominantly network-based, targeting HTTP(S) endpoints, and the scripts are suitable for both vulnerability validation and exploitation. The codebase is mature, with operational exploits for each vulnerability, and is a valuable resource for penetration testers and red teamers.
This repository contains two Python scripts and a README for exploiting CVE-2020-10199, a remote command execution vulnerability in Sonatype Nexus Repository Manager OSS/Pro versions <= 3.21.1. The main exploit script (cve-2020-10199_cmd.py) authenticates to the target Nexus instance using provided credentials, obtains a session ID, and then sends a specially crafted HTTP POST request to the /service/rest/beta/repositories/go/group endpoint to execute arbitrary system commands. The script provides an interactive shell for the attacker. The POC script (cve-2020-10199_poc.py) is used to verify the presence of the vulnerability by sending a test payload and checking the response for evidence of code execution. Both scripts require valid credentials and session tokens, and target the same vulnerable endpoint. The README provides usage instructions and context. No hardcoded IPs or domains are present; the scripts require user-supplied target information.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.