CyberRota Analysis
AI-GeneratedNexus Repository 3 is susceptible to stored cross-site scripting (XSS), allowing users with specific permissions to inject malicious scripts into blob store names. This vulnerability can lead to the execution of harmful scripts in the browsers of other users accessing system health-check status, potentially compromising user data and session integrity. Organizations using Nexus Repository 3 should prioritize upgrading to version 3.95.0 to mitigate this risk.
Original NVD Description
Nexus Repository 3 was found to be vulnerable to stored cross-site scripting (XSS). A user with the nexus:blobstores:create or nexus:blobstores:update permission could set a blob store name containing malicious script content, which would later execute in the browser of another user viewing system health-check status. This issue has been fixed in version 3.95.0.