PT-2024-4555 · Sonatype · Sonatype Nexus Repository 3+1
CVE-2024-4956
·
Published
2024-05-16
·
Updated
2026-09-07
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Sonatype Nexus Repository versions prior to 3.68.1
Description
A path traversal issue exists in Sonatype Nexus Repository 3 due to improper restriction of directory path names. This allows an unauthenticated remote attacker to read sensitive system files and protected information. The flaw can be exploited to access OrientDB
.pcl files, which may contain Apache Shiro 1 hashes used for authentication. Over 118,000 potentially affected devices have been identified.Recommendations
Update to version 3.68.1.
Exploit
Fix
DoS
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nexus Repository Manager
Sonatype Nexus Repository 3