logo

Unauthenticated Path Traversal in Nexus Repository Manager 3

ID: 187b7bd6-d6f6-5523-89de-b685375b371b

STIX ID: report--187b7bd6-d6f6-5523-89de-b685375b371b

Feed Name: Kudelski Security

Threat Score
80/100

Date Published: 2024-06-03

Date Updated: 2026-07-22

...
...

A critical unauthenticated path-traversal vulnerability affecting Nexus Repository Manager v3 (< 3.68.1) allows attackers to craft URLs that download arbitrary files from the host, potentially exposing sensitive items such as memory contents, database files, API keys and SSH keys; the report advises urgent upgrade to 3.68.1+, auditing authentication and webserver logs (looking for patterns like %2f or references to id_rsa, bash_history, /db/, /proc/), inspecting SSH keys, and resetting credentials if compromise is suspected.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.