PT-2024-4555 · Sonatype · Sonatype Nexus Repository 3+1

Published

2024-05-16

·

Updated

2026-03-10

·

CVE-2024-4956

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Sonatype Nexus Repository versions prior to 3.68.1
Description The issue is a path traversal vulnerability that allows an unauthenticated attacker to read system files. This vulnerability has been identified in Sonatype Nexus Repository 3 and can be exploited to access sensitive system files without authentication. The vulnerability is considered to have a high severity and has the potential for supply chain attacks due to the widespread use of the affected software. Over 118,000 results have been found on a specific search engine, indicating a large number of potentially affected systems.
Recommendations To resolve the issue, update Sonatype Nexus Repository to version 3.68.1 or later. This update fixes the path traversal vulnerability and prevents unauthorized access to system files. As a temporary workaround, consider restricting access to the vulnerable module or function until the patch is applied.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-05059
CVE-2024-4956

Affected Products

Nexus Repository Manager
Sonatype Nexus Repository 3