CVE-2024-5082: Nexus Repository 2 - Remote Code Execution
Published Nov 14, 2024
·Updated
A Remote Code Execution vulnerability has been discovered in Sonatype Nexus Repository 2.
This issue affects Nexus Repository 2 OSS/Pro versions up to and including 2.15.1.
Affected Software
1 affected component
Sonatype Nexus Repository 2<=2.15.1
Event History
Nov 14, 2024
CVE Published
via MITRE·02:58 AM
Data Sourced
via MITRE·02:58 AM
DescriptionWeakness
Data Sourced
via NVD·03:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-5082?
CVE-2024-5082 is classified as a critical vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2024-5082?
To remediate CVE-2024-5082, upgrade Sonatype Nexus Repository 2 to version 2.15.2 or later.
3
What versions of Nexus Repository 2 are affected by CVE-2024-5082?
CVE-2024-5082 affects all versions of Nexus Repository 2 OSS/Pro up to and including 2.15.1.
4
What type of vulnerability is CVE-2024-5082?
CVE-2024-5082 is a Remote Code Execution vulnerability.
5
Who is affected by CVE-2024-5082?
Any organization using Sonatype Nexus Repository 2 up to version 2.15.1 is at risk due to CVE-2024-5082.