CVE-2024-5082 is a remote code execution vulnerability in Sonatype Nexus Repository 2 OSS/Pro versions up to and including 2.15.1. The vulnerability allows an attacker to execute arbitrary code on the server hosting the Nexus Repository, potentially leading to full system compromise.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone Python proof-of-concept exploit for CVE-2024-5082 affecting Sonatype Nexus Repository Manager 2. It contains two files: a README describing the vulnerability and usage, and a single executable Python script, cve_2024_5082.py, which is the exploit entry point. The exploit targets Nexus 2.x through 2.15.1 by abusing repository content handling and Velocity template processing. It generates a unique Maven-style path, uploads a crafted maven-metadata.xml file containing a Velocity template, updates the corresponding Nexus attributes endpoint to set contentGenerator to velocity, and then performs a GET request on the uploaded artifact to trigger server-side template evaluation. The template uses Java reflection to access java.lang.Runtime and execute a bash command. The payload is operational rather than a mere detector: it constructs a base64-encoded bash reverse shell that connects from the Nexus host to an attacker-supplied listener IP and TCP port. The script also prints a response preview and checks for the marker string POC_COMPLETE to confirm template execution. After triggering, it attempts cleanup by deleting the uploaded artifact. Network interaction is entirely over HTTP(S) using urllib with Basic Authentication. The main fingerprintable target paths are /service/local/repositories/<repo>/content/<relative> for artifact upload/trigger/cleanup and /service/local/repositories/<repo>/content//.nexus/attributes/<relative> for changing the content generator. The exploit requires valid Nexus credentials with sufficient repository write/update permissions and a target configuration where the vulnerable Nexus instance can reach the attacker listener for the reverse-shell callback.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.