PT-2024-4555 · Sonatype · Sonatype Nexus Repository 3+1

CVE-2024-4956

·

Published

2024-05-16

·

Updated

2026-09-07

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Sonatype Nexus Repository versions prior to 3.68.1
Description A path traversal issue exists in Sonatype Nexus Repository 3 due to improper restriction of directory path names. This allows an unauthenticated remote attacker to read sensitive system files and protected information. The flaw can be exploited to access OrientDB .pcl files, which may contain Apache Shiro 1 hashes used for authentication. Over 118,000 potentially affected devices have been identified.
Recommendations Update to version 3.68.1.

Exploit

Fix

DoS

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-05059
CVE-2024-4956

Affected Products

Nexus Repository Manager
Sonatype Nexus Repository 3