CVE-2020-15871 | Nexus Repository ManagerÔ¶³Ì´úÂëÖ´Ðзì϶¹«¸æ

°ä²¼¹¦·ò 2020-08-04

0x00 ·ì϶¸ÅÊö


CVE   ID

CVE-2020-15871

ʱ    ¼ä

2020-08-04

Àà   ÐÍ

RCE

µÈ    ¼¶

ÑϳÁ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°ÏìÁìÓò

Nexus Repository Manager 3 OSS / Pro <= 3.25.0


0x01 ·ì϶ÏêÇé


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


2020Äê7ÔÂ29ÈÕ£¬Sonatype°ä²¼°²È«²¼¸æ£¬½¨¸´ÁËÒ»¸öNexus Repository Manager 3 Ô¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2020-15871£©¡£Æ¾¾ÝSonatype¹ÙÍøµÄÃèÊöÓÐÊʵ±È¨Ï޵Ĺ¥»÷Õß¿ÉÀûÓø÷ì϶ִÐÐËÁÒâ´úÂë¡£

Sonatype Nexus Repository Manager£¨NXRM£©ÊÇÃÀ¹úSonatype¹«Ë¾µÄÒ»¿îMaven²Ö¿âÖÎÀíÆ÷£¬ËüÖØÒªÓÃÓÚ²Ö¿âÖÎÀíºÍËÑË÷µÈÖ°ÄÜ¡£

ƾ¾ÝĿǰFOFAϵͳ×îÐÂͳ¼ÆÊý¾Ý£¬ÏÔʾȫÇòÁìÓòÄÚ£¨app="Nexus-Repository-Manager"£©¹²ÓÐ27865¸öÓйطþÎñ¶Ô±íÊ¢¿ª¡£ÖйúʹÓÃÊýÁ¿×î¶à¹²ÓÐ13841¸ö£¬ÃÀ¹úµÚ¶þ¹²ÓÐ5293¸ö£¬µÂ¹úµÚÈý¹²ÓÐ2162¸ö¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


0x02 ´ëÖý¨Òé


Ŀǰ³§ÉÌÒѰ䲼а汾3.25.1£¬ÏÂÔØÁ´½Ó£º

https://help.sonatype.com/repomanager3/download

ÓйØÉý¼¶µÄ¾ßÌåÐÅÏ¢£¬²Î¿¼ÒÔÏÂÁ´½Ó£º

https://support.sonatype.com/hc/zh-CN/articles/115000350007


0x03 ÓйØÐÂÎÅ


https://www.security-database.com/detail.php?alert=CVE-2020-15871


0x04 ²Î¿¼Á´½Ó


https://support.sonatype.com/hc/en-us/articles/360052192693-CVE-2020-15871-Nexus-Repository-Manager-3-Remote-Code-Execution-2020-07-29


0x05 ¹¦·òÏß


2020-07-29 Sonatype°ä²¼°²È«²¼¸æ

2020-08-04 VSRC°ä²¼·ì϶¹«¸æ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾