CyberRota Analysis
AI-GeneratedNexus Repository 3 is vulnerable due to inadequate Server-Side Request Forgery (SSRF) protections for HTTP redirect targets from proxy repository upstream servers. This flaw allows any user with read access to a compromised upstream server to potentially access sensitive internal network information or cloud metadata, including IAM credentials. Organizations using Nexus Repository 3, especially those with anonymous access enabled, should prioritize addressing this vulnerability to safeguard their sensitive data.
Original NVD Description
Nexus Repository 3 did not apply its existing Server-Side Request Forgery (SSRF) protections to HTTP redirect targets returned by proxy repository upstream servers. Any user with read access to a proxy repository backed by an attacker-controlled or compromised upstream server — including an anonymous user, if anonymous access is enabled — could receive a response from an internal network address or cloud metadata endpoint as repository content, potentially exposing sensitive information such as cloud IAM credentials.