Record summary

CVE-2024-5082 has a selected CVSS score of 7.1 (high); EIP currently links 1 repository PoC and 1 Nuclei template.

Description

A Remote Code Execution vulnerability has been discovered in Sonatype Nexus Repository 2.  This issue affects Nexus Repository 2 OSS/Pro versions up to and including 2.15.1.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jun 7, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Repository PoCs
1
Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 14, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Default status: unaffected

CVE List2.0.0 to ≤ 2.15.1affected
VulnCheckVersion data not supplied

Proofs of concept

1

Repository PoCs

GitHubh4mr3r/CVE-2024-5082Repository PoCby h4mr3rStars: 02 files

7.8 KiB

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryHIGHNexus Repository 2 - Remote Code Execution

A Remote Code Execution vulnerability has been discovered in Sonatype Nexus Repository 2.This issue affects Nexus Repository 2 OSS/Pro versions up to and including 2.15.1.

Impact

Attackers can exploit vulnerabilities to compromise the system.

Remediation

Update to the latest patched version addressing CVE-2024-5082.

Authorsiamnoooob, rootxharsh, pdresearch
Template tagscvecve2024intrusivenexussonartypevkevvuln
Shodan: html:"Nexus Repository"

Source: ProjectDiscovery

References

2