CyberRota Analysis
AI-GeneratedSonatype Nexus Repository 3 is vulnerable due to inadequate filtering of internal configuration keys in user-supplied task properties, allowing users with permission to create scheduled tasks to overwrite existing task configurations. This could lead to unintended modifications of critical tasks, potentially disrupting repository operations. Organizations using Nexus Repository 3 should prioritize this issue to mitigate risks associated with task misconfigurations.
Original NVD Description
Sonatype Nexus Repository 3 did not properly filter internal configuration keys from user-supplied task properties when creating or updating a scheduled task through the administrative UI. An account holding permission to create at least one scheduled task type could supply a crafted property value that caused the system to overwrite the configuration of an unrelated, existing task instead of creating a new one.