CVE-2024-5083
CVSS 3.1 Score 4.6 of 10 (medium)
Details
Summary
CVE-2024-5083 is a newly discovered Cross-site Scripting (XSS) vulnerability that affects Sonatype Nexus Repository 2. This issue allows an attacker to inject malicious scripts into web pages viewed by other users, potentially leading to unauthorized access or data theft. Affected versions include Nexus Repository 2 OSS and Pro, up to and including version 2.15.1. Successful exploitation of this vulnerability requires the attacker to have the ability to upload malicious content to the targeted repository. Users are strongly encouraged to update their repositories to the latest version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.