Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
https://github.com/kuckibf/Popular-CVEs
https://github.com/aleenzz/CVE-2020-10199
https://github.com/advisories/GHSA-g2f6-v5qh-h2mq
https://github.com/magicming200/CVE-2020-10199_CVE-2020-10204
https://github.com/jas502n/CVE-2020-10199
https://github.com/wsfengfan/CVE-2020-10199-10204
https://github.com/zhzyker/exphub
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-10199
https://support.sonatype.com/hc/en-us/articles/360044882533
http://packetstormsecurity.com/files/160835/Sonatype-Nexus-3.21.1-Remote-Code-Execution.html