CVE-2024-4956

HIGH NUCLEI LAB

Sonatype Nexus Repository <3.68.1 - Path Traversal

Title source: llm

Description

Path Traversal in Sonatype Nexus Repository 3 allows an unauthenticated attacker to read system files. Fixed in version 3.68.1.

Exploits (18)

exploitdb WORKING POC
by VeryLazyTech · pythonwebappsmultiple
https://www.exploit-db.com/exploits/52101
nomisec SCANNER 17 stars
by ifconfig-me · poc
https://github.com/ifconfig-me/CVE-2024-4956-Bulk-Scanner
nomisec WORKING POC 16 stars
by verylazytech · poc
https://github.com/verylazytech/CVE-2024-4956
nomisec WORKING POC 9 stars
by fin3ss3g0d · poc
https://github.com/fin3ss3g0d/CVE-2024-4956
nomisec SCANNER 3 stars
by Cappricio-Securities · poc
https://github.com/Cappricio-Securities/CVE-2024-4956
nomisec WORKING POC 3 stars
by GoatSecurity · poc
https://github.com/GoatSecurity/CVE-2024-4956
nomisec WORKING POC 3 stars
by erickfernandox · poc
https://github.com/erickfernandox/CVE-2024-4956
nomisec SCANNER 3 stars
by xungzzz · poc
https://github.com/xungzzz/CVE-2024-4956
nomisec WORKING POC 2 stars
by An00bRektn · poc
https://github.com/An00bRektn/shirocrack
nomisec WORKING POC 2 stars
by gmh5225 · poc
https://github.com/gmh5225/CVE-2024-4956
nomisec WORKING POC 1 stars
by Praison001 · poc
https://github.com/Praison001/CVE-2024-4956-Sonatype-Nexus-Repository-Manager
nomisec WORKING POC 1 stars
by thinhap · poc
https://github.com/thinhap/CVE-2024-4956-PoC
nomisec SCANNER 1 stars
by banditzCyber0x · poc
https://github.com/banditzCyber0x/CVE-2024-4956
nomisec WORKING POC
by amalpvatayam67 · poc
https://github.com/amalpvatayam67/day04-nexus-4956
nomisec WORKING POC
by Buff3st-0v3rfl0w · poc
https://github.com/Buff3st-0v3rfl0w/CVE-2024-4956
nomisec SCANNER
by art-of-defence · poc
https://github.com/art-of-defence/CVE-2024-4956
nomisec SCANNER
by UMASANKAR-MG · poc
https://github.com/UMASANKAR-MG/Path-Traversal-CVE-2024-4956
nomisec WORKING POC
by JolyIrsb · poc
https://github.com/JolyIrsb/CVE-2024-4956

Nuclei Templates (1)

Sonatype Nexus Repository Manager 3 - Local File Inclusion
HIGHVERIFIEDby ritikchaddha
FOFA: title="Nexus Repository Manager" || title="nexus repository manager"

Scores

CVSS v3 7.5
EPSS 0.9403
EPSS Percentile 99.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-22
Status published
Products (1)
Sonatype/Nexus Repository 3.0.0 - 3.68.0
Published May 16, 2024
Tracked Since Feb 18, 2026