{"id":71226,"date":"2025-10-08T21:45:35","date_gmt":"2025-10-08T18:15:35","guid":{"rendered":"https:\/\/afaghhosting.net\/blog\/cve-2025-9868-nexus-repository-2-ssrf-vulnerability-in-remote-browser-plugin\/"},"modified":"2025-10-08T21:45:35","modified_gmt":"2025-10-08T18:15:35","slug":"cve-2025-9868-nexus-repository-2-ssrf-vulnerability-in-remote-browser-plugin","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/cve-2025-9868-nexus-repository-2-ssrf-vulnerability-in-remote-browser-plugin\/","title":{"rendered":"CVE-2025-9868 &#8211; Nexus Repository 2 &#8211; SSRF Vulnerability in Remote Browser Plugin"},"content":{"rendered":"<p>CVE ID : CVE-2025-9868<\/p>\n<p>Published :  Oct. 8, 2025, 6:15 p.m. | 21\u00a0minutes ago<\/p>\n<p>Description : Server-Side Request Forgery (SSRF) in the Remote Browser Plugin in Sonatype Nexus Repository 2.x up to and including 2.15.2 allows unauthenticated remote attackers to exfiltrate proxy repository credentials via crafted HTTP requests.<\/p>\n<p>Severity: 8.7 | HIGH<\/p>\n<p>Visit the link for more details, such as CVSS details, affected products, timeline, and more&#8230;\u00a0<\/p>\n","protected":false},"excerpt":{"rendered":"<p>CVE ID : CVE-2025-9868 Published : Oct. 8, 2025, 6:15 p.m. | 21\u00a0minutes ago Description : Server-Side Request Forgery (SSRF) in the Remote Browser Plugin in Sonatype Nexus Repository 2.x up to and including 2.15.2 allows unauthenticated remote attackers to exfiltrate proxy repository credentials via crafted HTTP requests. Severity: 8.7 | HIGH Visit the link &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-71226","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/71226","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=71226"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/71226\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=71226"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=71226"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=71226"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}