Description
Path Traversal in Sonatype Nexus Repository 3 allows an unauthenticated attacker to read system files. Fixed in version 3.68.1.
Exploits (18)
exploitdb
WORKING POC
by VeryLazyTech · pythonwebappsmultiple
https://www.exploit-db.com/exploits/52101
nomisec
SCANNER
17 stars
by ifconfig-me · poc
https://github.com/ifconfig-me/CVE-2024-4956-Bulk-Scanner
nomisec
SCANNER
3 stars
by Cappricio-Securities · poc
https://github.com/Cappricio-Securities/CVE-2024-4956
nomisec
WORKING POC
1 stars
by Praison001 · poc
https://github.com/Praison001/CVE-2024-4956-Sonatype-Nexus-Repository-Manager
Nuclei Templates (1)
Sonatype Nexus Repository Manager 3 - Local File Inclusion
HIGHVERIFIEDby ritikchaddha
FOFA:
title="Nexus Repository Manager" || title="nexus repository manager"
Scores
CVSS v3
7.5
EPSS
0.9403
EPSS Percentile
99.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Lab Environment
COMMUNITY
Community Lab
+14 more repos
Details
CWE
CWE-22
Status
published
Products (1)
Sonatype/Nexus Repository
3.0.0 - 3.68.0
Published
May 16, 2024
Tracked Since
Feb 18, 2026