Nexus Repository ManagerÔ¶³ÌºÅÁîÖ´Ðзì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2019-09-16¡ñ·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-5475£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º8.8
¡ñÓ°Ïì°æ±¾
ÊÜÓ°ÏìµÄ°æ±¾
Nexus Repository Manager OSS/Pro version < 2.14.14
¡ñ·ì϶¸ÅÊö
Sonatype Nexus Repository Manager£¨NXRM£©ÊÇÃÀ¹úSonatype¹«Ë¾µÄÒ»¿îMaven²Ö¿âÖÎÀíÆ÷¡£
Nexus Repository ManagerµÄÄÚÖÃYum Repository²å¼þ´æÔÚÔ¶³ÌºÅÁîÖ´Ðзì϶¡£µ«ÊÇÕâ¸ö·ì϶±ØÒªadminȨÏÞÄÜÁ¦´¥·¢¡£ÈôÊÇĬÈϵÄadmin/admin123ÃÜÂëûÓÐÅú¸Ä£¬Ôò¿ÉÄܽáºÏÕâÒ»µãʵÏÖºÅÁîÖ´ÐС£·ì϶µãÔÚÓÚ£¬Yum Repository²å¼þÌṩÁËÒ»¸öcreaterepoºÍmergerepoºÅÁîõè¾¶µÄÖ°ÄÜ£¬Í¨¹ý½«Óû§ÊäÈëµÄºÅÁîÓë--version²ÎÊý½øÐÐÆ´½ÓºóÖ´ÐУ¬ÓÃÓÚÅжÏÓû§ÌṩµÄcreaterepo»òÕßmergerepoõè¾¶µÄºÅÁîÊÇ·ñ¿ÉÓ᣶øÕâ¸öõè¾¶Êǿɿصģ¬¿ÉËùÒÔËÁÒâºÅÁîµÄõè¾¶¡£²¢ÇÒûÓжÔÓû§ÊäÈëµÄºÅÁî×ö¹ýÂË¡£


¡ñ·ì϶ÑéÖ¤
POC£ºhttps://github.com/shadowsock5/Poc/blob/master/nexes-manager/CVE-2019-5475.py¡£
¡ñ½¨¸´½¨Òé
Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´·ì϶£¬²¹¶¡»ñÈ¡Á´½Ó£ºhttps://support.sonatype.com/hc/en-us/articles/360033490774-CVE-2019-5475-Nexus-Repository-Manager-2-OS-Command-Injection-2019-08-09¡£
¡ñ²Î¿¼Á´½Ó
https://support.sonatype.com/hc/en-us/articles/360033490774-CVE-2019-5475-Nexus-Repository-Manager-2-OS-Command-Injection-2019-08-09


¾©¹«Íø°²±¸11010802024551ºÅ