Sonatype Nexus version 3.21.1 suffers from an authenticated remote code execution vulnerability.
d8b1ad15495ef283352b6263e8b025b0ccf7349179f8c4e37eb756adbe9fb845
This Metasploit module exploits a Java Expression Language (EL) injection in Nexus Repository Manager versions up to and including 3.21.1 to execute code as the Nexus user. Tested against 3.21.1-01.
ba203b5afb621ea0d6a7f758f8ca6d420ae05e8217e8e4ec4f05955a24267ff2