CVE-2024-5083: Nexus Repository 2 - Stored XSS
Published Nov 14, 2024
·Updated
A stored Cross-site Scripting vulnerability has been discovered in Sonatype Nexus Repository 2
This issue affects Nexus Repository 2 OSS/Pro versions up to and including 2.15.1.
Affected Software
1 affected component
Sonatype Nexus Repository 2<=2.15.1
Event History
Nov 14, 2024
CVE Published
via MITRE·01:31 AM
Data Sourced
via MITRE·01:31 AM
DescriptionWeakness
Data Sourced
via NVD·02:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-5083?
CVE-2024-5083 is classified as a moderate severity stored Cross-site Scripting vulnerability.
2
How do I fix CVE-2024-5083?
To remediate CVE-2024-5083, upgrade to Sonatype Nexus Repository 2 version 2.15.2 or later.
3
What versions are affected by CVE-2024-5083?
CVE-2024-5083 affects Sonatype Nexus Repository 2 OSS and Pro versions up to and including 2.15.1.
4
Is CVE-2024-5083 a local or remote vulnerability?
CVE-2024-5083 is a remote vulnerability that allows attackers to exploit stored Cross-site Scripting remotely.
5
What are the potential impacts of CVE-2024-5083?
The potential impacts of CVE-2024-5083 include unauthorized data access and execution of malicious scripts in the context of users accessing the application.