CVE-2019-7238 is an incorrect access control vulnerability in Sonatype Nexus Repository Manager 3 versions before 3.15.0 that permits remote code execution. Exploitation has been observed in botnet campaigns involving Hide 'N Seek, DDG, WatchBog, and Sysrv. The specific vulnerable function and request-processing mechanism are not established.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
4 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This 32-file repository is primarily a reproducible vulnerable lab, with a manual exploit request embedded in its English and Chinese app READMEs rather than a standalone exploit program. The request POSTs JSON to /service/extdirect, invoking coreui_Component.previewAssets with a JEXL expression filter that calls Java Runtime.exec. Its basic hardcoded payload creates /tmp/success without authentication, provided the repository already contains a component. BCEL/classloader-based output retrieval is mentioned, but no corresponding implementation or reverse-shell payload is supplied. The root isoloom.yml describes one Linux/amd64 Nexus OSS 3.14.0 machine. app/ contains vendored Vulhub documentation and its original Compose configuration; base/ contains the original image Dockerfile; build/nexus/ removes the unauthenticated JDWP debugger from the published Vulhub image. Generated .isoloom/ assets support Docker, Kubernetes, a Vagrant Docker host, Proxmox, and six cloud providers. Docker removes the target's default route, while Kubernetes uses NetworkPolicies to restrict external egress. Cloud ingress permits SSH and Nexus only from an operator-supplied CIDR; Kubernetes publishes Nexus using a LoadBalancer and a broad port-8081 ingress policy. The five shell scripts test availability, the Nexus/3.14.0 Server header, ExtDirect endpoint presence, and outbound isolation. They do not execute the JEXL payload or prove exploitation. Seven Terraform files, one Ruby Vagrantfile, five shell scripts, and two Dockerfiles account for 15 code/build files; YAML deployment and CI definitions are additional configuration, and JEXL appears inside documentation. GitHub workflows validate and publish the lab through Isoloom, which is a provisioning tool here, not an exploit framework. Cleanup commands in provisioning and CI have legitimate lab-maintenance purposes and do not indicate a fake exploit. Notable inconsistencies: metadata describes getPreviousUsage, whereas the supplied exploit request uses previewAssets; the English guide says 3.21.1 in one setup sentence, but image references, checks, and the Chinese guide consistently identify 3.14.0. Documentation claims versions through 3.14.0 are affected. Upstream content is attributed to Vulhub commit 8fd63916f7a8711e2e01dda0d27237e4d6175d38; the analyzed repository's original URL, actual Git reference, and archive size were not supplied, so those fields remain empty or use zero as an unknown-size placeholder. Analysis is static; no deployment or exploitation was performed.
This repository contains a Python exploit script (CVE-2019-7238.py) targeting CVE-2019-7238, a remote code execution vulnerability in Sonatype Nexus Repository Manager 3 (versions prior to 3.15.0). The exploit abuses the /service/extdirect HTTP endpoint, which is vulnerable to JEXL injection, allowing unauthenticated attackers to execute arbitrary system commands on the server. The script supports both Linux and Windows targets, with a more elaborate payload staging process for Linux (using /etc/passwd, /tmp/passwd, and pwn.txt as temporary files to deliver and execute base64-encoded commands). The exploit is interactive, prompting the user for commands to execute on the target. The repository also includes a README.md with background information, references, and advisories. The exploit is operational and provides direct command execution capabilities, making it a practical tool for attackers or penetration testers.
This repository provides a working exploit for CVE-2019-7238, a remote code execution vulnerability in Sonatype Nexus Repository Manager 3.x (prior to 3.15.0). The exploit leverages a JEXL injection vulnerability in the /service/extdirect HTTP endpoint. The attacker crafts a POST request with a malicious JEXL expression that dynamically loads a serialized Java class (Test234) onto the server. This class executes arbitrary system commands and writes the output directly to the HTTP response, providing command execution with output (not blind). Repository structure: - README.md: Contains detailed exploit instructions, including the exact HTTP POST payload and technical notes on the vulnerability and exploitation process. - Test234.java: The Java class that is injected and executed on the server. It runs arbitrary commands and returns their output via the Jetty HTTP response. - nexus.md: Technical notes and debugging information about the vulnerability, JEXL expression handling, and Jetty internals. - trans2json.py: A helper script to generate the required JSON payload for the exploit. The exploit is operational and provides a clear path to RCE with output on vulnerable Nexus instances. The main attack vector is network-based, targeting the /service/extdirect endpoint.
This repository contains a working exploit for CVE-2019-7238, a critical unauthenticated remote code execution vulnerability in Sonatype Nexus Repository Manager 3.x versions prior to 3.15.0. The exploit is implemented in Python (CVE-2019-7238.py) and works by sending a specially crafted JSON payload to the /service/extdirect endpoint of a vulnerable Nexus instance. The payload leverages a JEXL injection to execute arbitrary Java code, which is used to run system commands on the server. The exploit does not require authentication and returns the output of the executed command. The README.md provides detailed usage instructions, example output, and demonstrates post-exploitation steps such as creating a new user and obtaining a shell via SSH. The repository is straightforward, with one main exploit script and documentation, and is operational in maturity, providing a real-world attack vector for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Nexus Repository Manager 3 vulnerability included in WatchBog’s exploit set for spreading and remote code execution.
A remote code execution vulnerability in Nexus Repository Manager listed as one of the exploits used by the Sysrv botnet for propagation.
A remote code execution vulnerability in Nexus Repository Manager listed as one of the exploits incorporated into the Sysrv botnet for propagation.
A Sonatype Nexus Repository Manager vulnerability previously exploited by Sysrv-hello during server-compromise activity.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.