Nexus Repository ManagerÔ¶³ÌÏÂÁîÖ´ÐÐÎó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2019-09-16¡ñÎó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-5475£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º8.8
¡ñÓ°Ïì°æ±¾
ÊÜÓ°ÏìµÄ°æ±¾
Nexus Repository Manager OSS/Pro version < 2.14.14
¡ñÎó²î¸ÅÊö
Sonatype Nexus Repository Manager£¨NXRM£©ÊÇÃÀ¹úSonatype¹«Ë¾µÄÒ»¿îMaven¿ÍÕ»ÖÎÀíÆ÷¡£
Nexus Repository ManagerµÄÄÚÖÃYum Repository²å¼þ±£´æÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î¡£¿ÉÊÇÕâ¸öÎó²îÐèÒªadminȨÏ޲Żª´¥·¢¡£ÈôÊÇĬÈϵÄadmin/admin123ÃÜÂëûÓÐÐ޸ģ¬Ôò¿ÉÄÜÍŽáÕâÒ»µãʵÏÖÏÂÁîÖ´ÐС£Îó²îµãÔÚÓÚ£¬Yum Repository²å¼þÌṩÁËÒ»¸öcreaterepoºÍmergerepoÏÂÁî·¾¶µÄ¹¦Ð§£¬Í¨¹ý½«Óû§ÊäÈëµÄÏÂÁîÓë--version²ÎÊý¾ÙÐÐÆ´½ÓºóÖ´ÐУ¬ÓÃÓÚÅжÏÓû§ÌṩµÄcreaterepo»òÕßmergerepo·¾¶µÄÏÂÁîÊÇ·ñ¿ÉÓ᣶øÕâ¸ö·¾¶Êǿɿصģ¬¿ÉÒÔÊÇí§ÒâÏÂÁîµÄ·¾¶¡£²¢ÇÒûÓжÔÓû§ÊäÈëµÄÏÂÁî×ö¹ýÂË¡£


¡ñÎó²îÑéÖ¤
POC£ºhttps://github.com/shadowsock5/Poc/blob/master/nexes-manager/CVE-2019-5475.py¡£
¡ñÐÞ¸´½¨Òé
ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£¬²¹¶¡»ñÈ¡Á´½Ó£ºhttps://support.sonatype.com/hc/en-us/articles/360033490774-CVE-2019-5475-Nexus-Repository-Manager-2-OS-Command-Injection-2019-08-09¡£
¡ñ²Î¿¼Á´½Ó
https://support.sonatype.com/hc/en-us/articles/360033490774-CVE-2019-5475-Nexus-Repository-Manager-2-OS-Command-Injection-2019-08-09


¾©¹«Íø°²±¸11010802024551ºÅ