Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2024-4956 PoC — Nexus Repository 3 - Path Traversal

Source
Associated Vulnerability
Title: Nexus Repository 3 - Path Traversal (CVE-2024-4956)
Description:Path Traversal in Sonatype Nexus Repository 3 allows an unauthenticated attacker to read system files. Fixed in version 3.68.1.
Description
CVE-2024-4956 Python exploitation utility
Readme
# cve-2024-4956

CVE-2024-4956是一个在Sonatype Nexus Repository 3中发现的严重路径遍历漏洞。该漏洞允许未经身份验证的攻击者利用应用程序,访问敏感的系统文件,从而可能导致机密数据泄露。

## **** 漏洞概述

CVE-2024-4956的主要问题在于Nexus Repository 3处理用户提供路径的方式。攻击者可以构造恶意URL,利用路径遍历技术,绕过安全限制,访问本应无法访问的文件。这种访问可能包括配置文件、应用日志等敏感信息。

## **** 技术细节

- **漏洞类型**:路径遍历(CWE-22)
  
- **影响版本**:所有版本的Sonatype Nexus Repository 3,直到3.68.0均受到影响。该漏洞在3.68.1版本中已修复。

- **CVSS评分**:7.5(高)

攻击者可以通过构造如下形式的请求来利用该漏洞:

```
GET /%2f%2f%2f%2f%2f%2f..%2f..%2f..%2f..%2f..%2f..%2f../etc/passwd HTTP/1.1
Host: localhost
```

此请求试图访问`/etc/passwd`文件,展示了如何通过路径遍历获取系统文件。

## **** 影响与后果

成功利用CVE-2024-4956可能导致以下后果:

- **数据窃取**:攻击者能够访问并窃取用户名、密码、访问令牌等机密信息。
  
- **软件开发流程中断**:访问或修改Nexus Repository中的关键配置文件可能会干扰软件开发和部署流程。

- **持久性威胁**:提取的凭证或系统环境信息可被攻击者用于在网络中建立持久性存在。

## **** 修复建议

Sonatype已发布3.68.1版本以修复此漏洞。建议用户尽快升级到此版本,以降低风险。如果无法立即升级,Sonatype提供了一种临时解决方案,即修改`jetty.xml`配置文件,但这可能带来其他安全隐患,因此应谨慎使用。

## **** 检测与监控

安全团队可以使用Web应用安全扫描器(WASS)检测Nexus Repository中的潜在路径遍历漏洞。此外,监控系统日志以发现对未授权文件的可疑访问尝试也是有效的防范措施。

总之,CVE-2024-4956是Sonatype Nexus Repository 3中的一个重大漏洞,系统管理员应优先考虑更新至3.68.1版本,并实施持续监控,以确保软件开发生命周期的整体安全。
File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →