CVE-2024-5082: Sonatype Nexus Repository

High severity, CVSS 7.1. EPSS: 2.7% chance of exploitation in the next 30 days.

A Remote Code Execution vulnerability has been discovered in Sonatype Nexus Repository 2.  This issue affects Nexus Repository 2 OSS/Pro versions up to and including 2.15.1.

Affected products

  • Sonatype Nexus Repository: from 2.0.0, up to and including 2.15.1

Published 2024-11-14. Last modified 2026-06-17.