CyberRota Analysis
AI-GeneratedNexus Repository 3 is susceptible to Server-Side Request Forgery (SSRF) through its SSL Certificate Retrieval endpoint, allowing users with the nexus:ssl-truststore:read permission to trigger outbound connections to internal or restricted network hosts. This vulnerability could lead to unauthorized access to sensitive internal resources. Organizations using affected versions of Nexus Repository, particularly those with sensitive internal networks, should prioritize remediation to mitigate potential security risks.
Original NVD Description
Nexus Repository 3 is vulnerable to Server-Side Request Forgery (SSRF) via the SSL Certificate Retrieval endpoint. A user holding the nexus:ssl-truststore:read permission could cause the server to initiate outbound connections to internal or otherwise restricted network hosts. This issue affects Nexus Repository 3.0.0 through versions prior to 3.94.0.