Due to a regression introduced in version 3.83.0, a security header is no longer applied to certain user-uploaded content served from repositories. This may allow an authenticated attacker with repository upload privileges to exploit a stored cross-site scripting (XSS) vulnerability with user context.
Metrics
Affected Vendors & Products
References
History
Thu, 04 Dec 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 04 Dec 2025 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Due to a regression introduced in version 3.83.0, a security header is no longer applied to certain user-uploaded content served from repositories. This may allow an authenticated attacker with repository upload privileges to exploit a stored cross-site scripting (XSS) vulnerability with user context. | |
| Title | Nexus Repository 3 - Stored Cross-Site Scripting (XSS) | |
| First Time appeared |
Sonatype
Sonatype nexus Repository Manager |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:sonatype:nexus_repository_manager:3.83.0:*:*:*:*:*:*:* cpe:2.3:a:sonatype:nexus_repository_manager:3.83.1:*:*:*:*:*:*:* cpe:2.3:a:sonatype:nexus_repository_manager:3.83.2:*:*:*:*:*:*:* cpe:2.3:a:sonatype:nexus_repository_manager:3.84.0:*:*:*:*:*:*:* cpe:2.3:a:sonatype:nexus_repository_manager:3.84.1:*:*:*:*:*:*:* cpe:2.3:a:sonatype:nexus_repository_manager:3.85.0:*:*:*:*:*:*:* cpe:2.3:a:sonatype:nexus_repository_manager:3.86.0:*:*:*:*:*:*:* cpe:2.3:a:sonatype:nexus_repository_manager:3.86.2:*:*:*:*:*:*:* |
|
| Vendors & Products |
Sonatype
Sonatype nexus Repository Manager |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Sonatype
Published: 2025-12-04T18:16:56.582Z
Updated: 2025-12-04T20:00:41.734Z
Reserved: 2025-11-20T20:16:15.824Z
Link: CVE-2025-13488
Updated: 2025-12-04T18:55:04.371Z
Status : Received
Published: 2025-12-04T19:16:01.937
Modified: 2025-12-04T19:16:01.937
Link: CVE-2025-13488
No data.