Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
day04-nexus-4956 — Nexus Repository 3 Path Traversal (CVE-2024-4956) | Kitploit
Tools/GitHubGitHub/amalpvatayam67/day04-nexus-4956
Container SecurityVulnerability AnalysisExploitationWeb Application ExploitationLearning & EducationLabs & Practice
GitHubamalpvatayam67/day04-nexus-4956

day04-nexus-4956

Nexus Repository 3 Path Traversal (CVE-2024-4956)

View Repository
91 year agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Day 4 – Nexus Repository 3 Path Traversal (CVE-2024-4956)

What: Unauthenticated path traversal lets anyone download arbitrary files with a crafted URL.
Vuln: Affects Nexus Repo 3 versions ≤ 3.68.0. Fixed in 3.68.1.
Source: Sonatype advisory + NVD.
Safety: Lab is local-only. Don’t target systems you don’t own.

Setup

docker build -t day4-nexus-4956 .
docker run -d -p 8081:8081 --name day4 day4-nexus-4956
# Boot takes ~1–2 minutes; watch: docker logs -f day4
curl -I httphttp://localhost:8081/

! If you stuck you can use ./exploit.sh (after the container is running)

Download Tool