CVE-2024-4956: Nexus Repository 3 - Path Traversal
Published May 16, 2024
·Updated
Path Traversal in Sonatype Nexus Repository 3 allows an unauthenticated attacker to read system files. Fixed in version 3.68.1.
Affected Software
1 affected component
Sonatype Nexus Repository 3<3.68.1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Nexus Repository 3to a version that resolves this vulnerability.Fixed in 3.68.1
Event History
May 16, 2024
CVE Published
via MITRE·03:31 PM
Data Sourced
via MITRE·03:31 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeakness
Mar 28, 2025
Exploit Published
12:00 AM
Known Exploited
05:41 PM
Mar 30, 57258
Event
via FIRST·09:30 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-4956?
CVE-2024-4956 has been classified as a high severity vulnerability due to the potential for unauthorized access to sensitive system files.
2
How do I fix CVE-2024-4956?
To fix CVE-2024-4956, upgrade to Sonatype Nexus Repository 3 version 3.68.1 or later.
3
Who is affected by CVE-2024-4956?
CVE-2024-4956 affects users of Sonatype Nexus Repository 3 versions prior to 3.68.1.
4
What type of vulnerability is CVE-2024-4956?
CVE-2024-4956 is a path traversal vulnerability that allows unauthenticated attackers to read system files.
5
Is authentication required to exploit CVE-2024-4956?
No, CVE-2024-4956 can be exploited by unauthenticated attackers.