Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

PRP: Request Nexus Repository 3 Arbitrary File Read (CVE-2024-4956) #498

Open
W0ngL1 opened this issue Jun 6, 2024 · 0 comments
Open

PRP: Request Nexus Repository 3 Arbitrary File Read (CVE-2024-4956) #498

W0ngL1 opened this issue Jun 6, 2024 · 0 comments
Assignees
Labels
Contributor queue When a contributor has already one issue/PR in review, we put the following ones on hold with this.

Comments

@W0ngL1
Copy link
Contributor

W0ngL1 commented Jun 6, 2024

Hi there.

I would like to start implementing a plugin to detect Nexus Repository 3 Arbitrary File Read (CVE-2024-4956). This vulnerability was published on May 2024. I believe AI software may also use this.

References:
https://nvd.nist.gov/vuln/detail/CVE-2024-4956

Description:
Sonatype Nexus Repository Manager is an open-source repository management system developed by Sonatype. It is designed to organize, store, and distribute software components, binaries, and build artifacts across an organization's software development lifecycle. Nexus supports a wide variety of repository formats, including Maven, npm, NuGet, Docker, and more, making it a versatile tool for managing dependencies in various programming languages and environments.

Affected Versions:
Sonatype Nexus Repository < 3.68.1

Thanks.

@tooryx tooryx added the Contributor queue When a contributor has already one issue/PR in review, we put the following ones on hold with this. label Jul 16, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Contributor queue When a contributor has already one issue/PR in review, we put the following ones on hold with this.
Projects
None yet
Development

No branches or pull requests

2 participants