Security Research

CVE-2024-4956 Sonatype Nexus OSS Path Traversal: from artifact repository to arbitrary file read

#Vulnerability Analysis#Code Audit#Web Security
Dark dossier of artifact repository path-traversal pointer and file read

Sonatype Nexus Repository OSS does not sufficiently filter paths, letting an attacker craft a special URL to read arbitrary files on the server without authentication.

Unlock to view this content.