Server-side request forgery in the Remote Browser Plugin
An unauthenticated attacker can use the Remote Browser Plugin to send arbitrary HTTP GET requests to servers the attacker controls. If a proxy repository is configured with authentication, its credentials may be leaked.
- Affected
- All Nexus Repository Manager 2.x OSS and Pro versions. The CVE record lists 2.0.0 through 2.15.2.
- Fix for Nexus 2
- None. The advisory says Sonatype will not release a fix.
- Severity
- CVSS 4.0 score 8.7, High, rated by Sonatype. NVD has not given it a score of its own.
- NVD status
- Deferred
Sonatype's advisory suggests removing the Remote Browser Plugin, which it says is enabled by default, and placing the server behind a restrictive reverse proxy or firewall that limits outbound connections.
Sources: NVD record for CVE-2025-9868; Sonatype advisory for CVE-2025-9868.