CVE-2024-5764
Last modified
CVE-2024-5764 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Use of Hard-coded Credentials vulnerability in Sonatype Nexus Repository has been discovered in the code responsible for encrypting any secrets stored in the Nexus Repository configuration database (SMTP or HTTP proxy credentials, user tokens, tokens, among others). The affected versions relied on a static hard-coded encryption passphrase. EPSS estimates a 0.39% chance of exploitation in the next 30 days.
Description
Use of Hard-coded Credentials vulnerability in Sonatype Nexus Repository has been discovered in the code responsible for encrypting any secrets stored in the Nexus Repository configuration database (SMTP or HTTP proxy credentials, user tokens, tokens, among others). The affected versions relied on a static hard-coded encryption passphrase. While it was possible for an administrator to define an alternate encryption passphrase, it could only be done at first boot and not updated. This issue affects Nexus Repository: from 3.0.0 through 3.72.0.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sonatype | Nexus Repository Manager | >= 3.0.0, < 3.73.0 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-5764?
How severe is CVE-2024-5764?
How do I fix CVE-2024-5764?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-57634An issue in the exp_copy component of MonetDB Server v11.49.…7.5
- CVE-2024-57635An issue in the chash_array component of openlink virtuoso-o…7.5
- CVE-2024-57636An issue in the itc_sample_row_check component of openlink v…7.5
- CVE-2024-57637An issue in the dfe_unit_gb_dependant component of openlink …7.5
- CVE-2024-57638An issue in the dfe_body_copy component of openlink virtuoso…7.5
- CVE-2024-57639An issue in the dc_elt_size component of openlink virtuoso-o…7.5
- CVE-2024-57640An issue in the dc_add_int component of openlink virtuoso-op…7.5
- CVE-2024-57641An issue in the sqlexp component of openlink virtuoso-openso…7.5
- CVE-2024-57642An issue in the dfe_inx_op_col_def_table component of openli…7.5
- CVE-2024-57643An issue in the box_deserialize_string component of openlink…7.5
- CVE-2024-57644An issue in the itc_hash_compare component of openlink virtu…7.5
- CVE-2024-57645An issue in the qi_inst_state_free component of openlink vir…7.5
Are you affected by CVE-2024-5764?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
