← back
CVE-2024-5082highobserved exploitationCWE-94

Nexus Repository 2 - Remote Code Execution

78Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actcvss 7.1epss 2.0%
from disclosure to weapon608 days
Published on NVDNov 14
1st PoC+608d
VulnCheck+205d
exploitation probability
2.0%top 22% of all CVEs
observed exploitation
yesVulnCheck
1 public exploit(s)
A Remote Code Execution vulnerability has been discovered in Sonatype Nexus Repository 2.  This issue affects Nexus Repository 2 OSS/Pro versions up to and including 2.15.1.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:L/SA:N
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.