CVE-2024-5082 is a Remote Code Execution (RCE) vulnerability impacting Sonatype Nexus Repository 2 OSS/Pro versions up to and including 2.15.1. This high-severity flaw, rated 7.1 CVSS, allows an unauthenticated attacker to execute arbitrary code with low attack complexity. While there is no evidence of active exploitation or public exploit code on platforms like Metasploit or ExploitDB, Nuclei templates exist for detecting this vulnerability. Community discussion and media coverage for this CVE are currently minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Sonatype | Nexus Repository | >= 2.0.0, <= 2.15.1CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.