CVE-2024-4956: Sonatype Nexus Repository
High severity, CVSS 7.5. EPSS: 18.2% chance of exploitation in the next 30 days.
Path Traversal in Sonatype Nexus Repository 3 allows an unauthenticated attacker to read system files. Fixed in version 3.68.1.
Affected products
- Sonatype Nexus Repository: from 3.0.0, up to and including 3.68.0
Published 2024-05-16. Last modified 2026-06-17.