CVE-2020-10199| Nexus Repository ManagerÔ¶³Ì´úÂëÖ´Ðзì϶¹«¸æ
°ä²¼¹¦·ò 2020-04-020x00 ·ì϶¸ÅÊö
CVE ID
CVE-2020-10199
ʱ ¼ä
2020-04-02
Àà ÐÍ
Ô¶³Ì´úÂëÖ´ÐÐ
µÈ ¼¶
¸ßΣ
Ô¶³ÌÀûÓÃ
ÊÇ
Ó°ÏìÁìÓò
Nexus Repository Manager OSS/Pro 3.x
<= 3.21.1
0x01 ·ì϶ÏêÇé
Sonatype Nexus ÊÇÒ»¸ö Maven µÄ²Ö¿âÖÎÀíϵͳ£¬ËüÌṩÁË׳´óµÄ²Ö¿âÖÎÀí¡¢¹¹¼þËÑË÷µÈÖ°ÄÜ£¬²¢ÇÒÄܹ»ÓÃÀ´´î½¨ Maven ²Ö¿â˽·þ£¬ÔÚ´úÀíÔ¶³Ì²Ö¿âµÄÍ¬Ê±ÊØ»¤±¾µØ²Ö¿â£¬ÒÔ½Ú¼ó´ø¿íºÍ¹¦·ò¡£
ÔÚ Nexus Repository Manager OSS/Pro 3.21.1 ¼°Ö®Ç°µÄ°æ±¾ÖУ¬¾¹ýÊÚȨÈÏÖ¤µÄ¹¥»÷Õߣ¬Äܹ»Í¨¹ý JavaEL ±í°×ʽעÈëÔì³ÉÔ¶³Ì´úÂëÖ´ÐУ¬»ñȡϵͳȨÏÞ¡£
0x02 ´ëÖý¨Òé
¸üРNexus Repository Manager µ½3.21.2»ò¸ü¸ß°æ±¾£º
https://help.sonatype.com/repomanager3/download/
0x03 ÓйØÐÂÎÅ
https://support.sonatype.com/hc/en-us/articles/360044882533
0x04 ²Î¿¼Á´½Ó
https://nvd.nist.gov/vuln/detail/CVE-2020-10199
0x05 ¹¦·òÏß
2020-03-31 Sonatype¹Ù·½°ä²¼·ì϶¹«¸æ
2020-04-01 CVE °ä²¼¸Ã·ì϶


¾©¹«Íø°²±¸11010802024551ºÅ