PT-2024-9211 · Sonatype · Sonatype Nexus Repository+1

Published

2024-05-17

·

Updated

2024-11-19

·

CVE-2024-5082

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions: Sonatype Nexus Repository 2 versions up to and including 2.15.1
Description: A Remote Code Execution issue has been discovered, related to incorrect code generation management. This allows a remote attacker to execute arbitrary code by publishing Maven artifacts, potentially leading to system compromise.
Recommendations: For versions up to and including 2.15.1, update to a version later than 2.15.1 to resolve the issue. As a temporary workaround, consider restricting access to the Maven artifact publication feature until a patch is available.

Fix

RCE

Code Injection

Weakness Enumeration

Related Identifiers

BDU:2024-10899
CVE-2024-5082

Affected Products

Nexus Repository Manager
Sonatype Nexus Repository