Nexus Repository ManagerÔ¶³ÌºÅÁîÖ´Ðзì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-09-16

¡ñ·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-5475£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º8.8


¡ñÓ°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾


Nexus Repository Manager OSS/Pro version < 2.14.14


¡ñ·ì϶¸ÅÊö


Sonatype Nexus Repository Manager£¨NXRM£©ÊÇÃÀ¹úSonatype¹«Ë¾µÄÒ»¿îMaven²Ö¿âÖÎÀíÆ÷¡£


Nexus Repository ManagerµÄÄÚÖÃYum Repository²å¼þ´æÔÚÔ¶³ÌºÅÁîÖ´Ðзì϶¡£µ«ÊÇÕâ¸ö·ì϶±ØÒªadminȨÏÞÄÜÁ¦´¥·¢¡£ÈôÊÇĬÈϵÄadmin/admin123ÃÜÂëûÓÐÅú¸Ä£¬Ôò¿ÉÄܽáºÏÕâÒ»µãʵÏÖºÅÁîÖ´ÐС£·ì϶µãÔÚÓÚ£¬Yum Repository²å¼þÌṩÁËÒ»¸öcreaterepoºÍmergerepoºÅÁîõè¾¶µÄÖ°ÄÜ£¬Í¨¹ý½«Óû§ÊäÈëµÄºÅÁîÓë--version²ÎÊý½øÐÐÆ´½ÓºóÖ´ÐУ¬ÓÃÓÚÅжÏÓû§ÌṩµÄcreaterepo»òÕßmergerepoõè¾¶µÄºÅÁîÊÇ·ñ¿ÉÓ᣶øÕâ¸öõè¾¶ÊǿɿصÄ£¬¿ÉËùÒÔËÁÒâºÅÁîµÄõè¾¶¡£²¢ÇÒûÓжÔÓû§ÊäÈëµÄºÅÁî×ö¹ýÂË¡£


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


¡ñ·ì϶ÑéÖ¤


POC£ºhttps://github.com/shadowsock5/Poc/blob/master/nexes-manager/CVE-2019-5475.py¡£


¡ñ½¨¸´½¨Òé


Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´·ì϶£¬²¹¶¡»ñÈ¡Á´½Ó£ºhttps://support.sonatype.com/hc/en-us/articles/360033490774-CVE-2019-5475-Nexus-Repository-Manager-2-OS-Command-Injection-2019-08-09¡£


¡ñ²Î¿¼Á´½Ó


https://support.sonatype.com/hc/en-us/articles/360033490774-CVE-2019-5475-Nexus-Repository-Manager-2-OS-Command-Injection-2019-08-09