Nexus Repository 3.x < 3.68.1 Path Traversal

high Web App Scanning Plugin ID 114284

Synopsis

Nexus Repository 3.x < 3.68.1 Path Traversal

Description

Nexus Repository version 3.x prior to 3.68.1 is affected by a Path Traversal allowing an attacker to create a URL returning any file for download, including system files outside the scope of the Nexus Repository application, without any authentication.

Solution

Upgrade to Nexus Repository Manager 3.68.1 or later.

See Also

https://support.sonatype.com/hc/en-us/articles/29416509323923-CVE-2024-4956-Nexus-Repository-3-Path-Traversal-2024-05-16

Plugin Details

Severity: High

ID: 114284

Type: remote

Published: 5/27/2024

Updated: 5/27/2024

Scan Template: basic, full, pci, scan

Risk Information

VPR

Risk Factor: Medium

Score: 6.1

CVSS v2

Risk Factor: Medium

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS Score Source: CVE-2024-4956

CVSS v3

Risk Factor: High

Base Score: 7.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CVSS Score Source: CVE-2024-4956

CVSS v4

Risk Factor: High

Base Score: 8.7

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

CVSS Score Source: Tenable

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 5/16/2024

Vulnerability Publication Date: 5/16/2024

Reference Information

CVE: CVE-2024-4956