Nexus Repository ManagerÔ¶³ÌÏÂÁîÖ´ÐÐÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-09-16

¡ñÎó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-5475£¬£¬ £¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬ £¬£¬£¬£¬CVSS·ÖÖµ£º8.8


¡ñÓ°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾


Nexus Repository Manager OSS/Pro version < 2.14.14


¡ñÎó²î¸ÅÊö


Sonatype Nexus Repository Manager£¨NXRM£©ÊÇÃÀ¹úSonatype¹«Ë¾µÄÒ»¿îMaven¿ÍÕ»ÖÎÀíÆ÷ ¡£¡£


Nexus Repository ManagerµÄÄÚÖÃYum Repository²å¼þ±£´æÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î ¡£¡£¿ÉÊÇÕâ¸öÎó²îÐèÒªadminȨÏ޲Żª´¥·¢ ¡£¡£ÈôÊÇĬÈϵÄadmin/admin123ÃÜÂëûÓÐÐ޸쬣¬ £¬£¬£¬£¬Ôò¿ÉÄÜÁ¬ÏµÕâÒ»µãʵÏÖÏÂÁîÖ´ÐÐ ¡£¡£Îó²îµãÔÚÓÚ£¬£¬ £¬£¬£¬£¬Yum Repository²å¼þÌṩÁËÒ»¸öcreaterepoºÍmergerepoÏÂÁî·¾¶µÄ¹¦Ð§£¬£¬ £¬£¬£¬£¬Í¨¹ý½«Óû§ÊäÈëµÄÏÂÁîÓë--version²ÎÊý¾ÙÐÐÆ´½ÓºóÖ´ÐУ¬£¬ £¬£¬£¬£¬ÓÃÓÚÅжÏÓû§ÌṩµÄcreaterepo»òÕßmergerepo·¾¶µÄÏÂÁîÊÇ·ñ¿ÉÓà ¡£¡£¶øÕâ¸ö·¾¶ÊǿɿصÄ£¬£¬ £¬£¬£¬£¬¿ÉÒÔÊÇí§ÒâÏÂÁîµÄ·¾¶ ¡£¡£²¢ÇÒûÓжÔÓû§ÊäÈëµÄÏÂÁî×ö¹ýÂË ¡£¡£


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø

ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


¡ñÎó²îÑéÖ¤


POC£ºhttps://github.com/shadowsock5/Poc/blob/master/nexes-manager/CVE-2019-5475.py ¡£¡£


¡ñÐÞ¸´½¨Òé


ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£¬£¬ £¬£¬£¬£¬²¹¶¡»ñÈ¡Á´½Ó£ºhttps://support.sonatype.com/hc/en-us/articles/360033490774-CVE-2019-5475-Nexus-Repository-Manager-2-OS-Command-Injection-2019-08-09 ¡£¡£


¡ñ²Î¿¼Á´½Ó


https://support.sonatype.com/hc/en-us/articles/360033490774-CVE-2019-5475-Nexus-Repository-Manager-2-OS-Command-Injection-2019-08-09