vendor:
Nexus Repository
by:
VeryLazyTech
4.1
CVSS
MEDIUM
Path Traversal
22
CWE
Product Name: Nexus Repository
Affected Version From: 3.53.0-01
Affected Version To: 3.53.0-01
Patch Exists: NO
Related CWE: CVE-2024-4956
CPE: Sonatype:Nexus_Repository:3.53.0-01
Platforms Tested: Ubuntu 20.04
2024
Sonatype Nexus Repository 3.53.0-01 – Path Traversal
The Sonatype Nexus Repository 3.53.0-01 is vulnerable to a path traversal exploit, allowing an attacker to access files and directories outside of the web root directory. This vulnerability has been assigned CVE-2024-4956.
Mitigation:
To mitigate this vulnerability, it is recommended to update to a patched version of Sonatype Nexus Repository beyond 3.53.0-01.