NONE · 0

CVE-2025-9868

Server-Side Request Forgery (SSRF) in the Remote Browser Plugin in Sonatype Nexus Repository 2.x up to and including 2.15.2 allows unauthenticated remote attackers to exfiltrate proxy repository crede...

Vulnerability Description

Server-Side Request Forgery (SSRF) in the Remote Browser Plugin in Sonatype Nexus Repository 2.x up to and including 2.15.2 allows unauthenticated remote attackers to exfiltrate proxy repository credentials via crafted HTTP requests.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2025-9868?

CVE-2025-9868 is a documented vulnerability. Server-Side Request Forgery (SSRF) in the Remote Browser Plugin in Sonatype Nexus Repository 2.x up to and including 2.15.2 allows unauthenticated remote attackers to exfiltrate proxy repository crede...

How severe is CVE-2025-9868?

CVSS scoring is not yet available for CVE-2025-9868. Check NVD for updates.

Is there a patch for CVE-2025-9868?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.