CVE-2020-15871 | Nexus Repository ManagerÔ¶³Ì´úÂëÖ´ÐÐÎó²îͨ¸æ

Ðû²¼Ê±¼ä 2020-08-04

0x00 Îó²î¸ÅÊö


CVE   ID

CVE-2020-15871

ʱ    ¼ä

2020-08-04

Àà   ÐÍ

RCE

µÈ    ¼¶

ÑÏÖØ

Ô¶³ÌʹÓÃ

ÊÇ

Ó°Ïì¹æÄ£

Nexus Repository Manager 3 OSS / Pro <= 3.25.0


0x01 Îó²îÏêÇé


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


2020Äê7ÔÂ29ÈÕ£¬SonatypeÐû²¼Ç徲ͨ¸æ£¬ÐÞ¸´ÁËÒ»¸öNexus Repository Manager 3 Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-15871£© ¡£Æ¾Ö¤Sonatype¹ÙÍøµÄÐÎòÓÐÊʵ±È¨Ï޵Ĺ¥»÷Õß¿ÉʹÓøÃÎó²îÖ´ÐÐí§Òâ´úÂë ¡£

Sonatype Nexus Repository Manager£¨NXRM£©ÊÇÃÀ¹úSonatype¹«Ë¾µÄÒ»¿îMaven¿ÍÕ»ÖÎÀíÆ÷£¬ËüÖ÷ÒªÓÃÓÚ¿ÍÕ»ÖÎÀíºÍËÑË÷µÈ¹¦Ð§ ¡£

ƾ֤ÏÖÔÚFOFAϵͳ×îÐÂͳ¼ÆÊý¾Ý£¬ÏÔʾȫÇò¹æÄ£ÄÚ£¨app="Nexus-Repository-Manager"£©¹²ÓÐ27865¸öÏà¹Ø·þÎñ¶ÔÍ⿪·Å ¡£ÖйúʹÓÃÊýÄ¿×î¶à¹²ÓÐ13841¸ö£¬ÃÀ¹úµÚ¶þ¹²ÓÐ5293¸ö£¬µÂ¹úµÚÈý¹²ÓÐ2162¸ö ¡£


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


0x02 ´¦Öóͷ£½¨Òé


ÏÖÔÚ³§ÉÌÒÑÐû²¼Ð°汾3.25.1£¬ÏÂÔØÁ´½Ó£º

https://help.sonatype.com/repomanager3/download

ÓйØÉý¼¶µÄÏêϸÐÅÏ¢£¬²Î¿¼ÒÔÏÂÁ´½Ó£º

https://support.sonatype.com/hc/zh-CN/articles/115000350007


0x03 Ïà¹ØÐÂÎÅ


https://www.security-database.com/detail.php?alert=CVE-2020-15871


0x04 ²Î¿¼Á´½Ó


https://support.sonatype.com/hc/en-us/articles/360052192693-CVE-2020-15871-Nexus-Repository-Manager-3-Remote-Code-Execution-2020-07-29


0x05 ʱ¼äÏß


2020-07-29 SonatypeÐû²¼Ç徲ͨ¸æ

2020-08-04 VSRCÐû²¼Îó²îͨ¸æ


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!