CVE-2020-10199| Nexus Repository ManagerÔ¶³Ì´úÂëÖ´Ðзì϶¹«¸æ

°ä²¼¹¦·ò 2020-04-02

0x00 ·ì϶¸ÅÊö


CVE   ID

CVE-2020-10199

ʱ    ¼ä

2020-04-02

Àà    ÐÍ

Ô¶³Ì´úÂëÖ´ÐÐ

µÈ    ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°ÏìÁìÓò

Nexus Repository Manager OSS/Pro 3.x <= 3.21.1



0x01 ·ì϶ÏêÇé




Sonatype Nexus ÊÇÒ»¸ö Maven µÄ²Ö¿âÖÎÀíϵͳ£¬ËüÌṩÁË׳´óµÄ²Ö¿âÖÎÀí¡¢¹¹¼þËÑË÷µÈÖ°ÄÜ£¬²¢ÇÒÄܹ»ÓÃÀ´´î½¨ Maven ²Ö¿â˽·þ£¬ÔÚ´úÀíÔ¶³Ì²Ö¿âµÄÍ¬Ê±ÊØ»¤±¾µØ²Ö¿â£¬ÒÔ½Ú¼ó´ø¿íºÍ¹¦·ò¡£


ÔÚ Nexus Repository Manager OSS/Pro 3.21.1 ¼°Ö®Ç°µÄ°æ±¾ÖУ¬¾­¹ýÊÚȨÈÏÖ¤µÄ¹¥»÷Õߣ¬Äܹ»Í¨¹ý JavaEL ±í°×ʽעÈëÔì³ÉÔ¶³Ì´úÂëÖ´ÐУ¬»ñȡϵͳȨÏÞ¡£


0x02 ´ëÖý¨Òé


¸üРNexus Repository Manager µ½3.21.2»ò¸ü¸ß°æ±¾£º

https://help.sonatype.com/repomanager3/download/


0x03 ÓйØÐÂÎÅ


https://support.sonatype.com/hc/en-us/articles/360044882533


0x04 ²Î¿¼Á´½Ó


https://nvd.nist.gov/vuln/detail/CVE-2020-10199


0x05 ¹¦·òÏß


2020-03-31 Sonatype¹Ù·½°ä²¼·ì϶¹«¸æ

2020-04-01 CVE °ä²¼¸Ã·ì϶