CVE-2020-15871 | Nexus Repository ManagerÔ¶³Ì´úÂëÖ´ÐÐÎó²îͨ¸æ

Ðû²¼Ê±¼ä 2020-08-04

0x00 Îó²î¸ÅÊö


CVE   ID

CVE-2020-15871

ʱ    ¼ä

2020-08-04

Àà   ÐÍ

RCE

µÈ    ¼¶

ÑÏÖØ

Ô¶³ÌʹÓÃ

ÊÇ

Ó°Ïì¹æÄ£

Nexus Repository Manager 3 OSS / Pro <= 3.25.0


0x01 Îó²îÏêÇé


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


2020Äê7ÔÂ29ÈÕ£¬£¬£¬SonatypeÐû²¼Ç徲ͨ¸æ£¬£¬£¬ÐÞ¸´ÁËÒ»¸öNexus Repository Manager 3 Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-15871£©¡£¡£ ¡£Æ¾Ö¤Sonatype¹ÙÍøµÄÐÎòÓÐÊʵ±È¨Ï޵Ĺ¥»÷Õß¿ÉʹÓøÃÎó²îÖ´ÐÐí§Òâ´úÂë¡£¡£ ¡£

Sonatype Nexus Repository Manager£¨NXRM£©ÊÇÃÀ¹úSonatype¹«Ë¾µÄÒ»¿îMaven¿ÍÕ»ÖÎÀíÆ÷£¬£¬£¬ËüÖ÷ÒªÓÃÓÚ¿ÍÕ»ÖÎÀíºÍËÑË÷µÈ¹¦Ð§¡£¡£ ¡£

ƾ֤ÏÖÔÚFOFAϵͳ×îÐÂͳ¼ÆÊý¾Ý£¬£¬£¬ÏÔʾȫÇò¹æÄ£ÄÚ£¨app="Nexus-Repository-Manager"£©¹²ÓÐ27865¸öÏà¹ØÐ§ÀͶÔÍ⿪·Å¡£¡£ ¡£ÖйúʹÓÃÊýÄ¿×î¶à¹²ÓÐ13841¸ö£¬£¬£¬ÃÀ¹úµÚ¶þ¹²ÓÐ5293¸ö£¬£¬£¬µÂ¹úµÚÈý¹²ÓÐ2162¸ö¡£¡£ ¡£


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


0x02 ´¦Öóͷ£½¨Òé


ÏÖÔÚ³§ÉÌÒÑÐû²¼Ð°汾3.25.1£¬£¬£¬ÏÂÔØÁ´½Ó£º

https://help.sonatype.com/repomanager3/download

ÓйØÉý¼¶µÄÏêϸÐÅÏ¢£¬£¬£¬²Î¿¼ÒÔÏÂÁ´½Ó£º

https://support.sonatype.com/hc/zh-CN/articles/115000350007


0x03 Ïà¹ØÐÂÎÅ


https://www.security-database.com/detail.php?alert=CVE-2020-15871


0x04 ²Î¿¼Á´½Ó


https://support.sonatype.com/hc/en-us/articles/360052192693-CVE-2020-15871-Nexus-Repository-Manager-3-Remote-Code-Execution-2020-07-29


0x05 ʱ¼äÏß


2020-07-29 SonatypeÐû²¼Ç徲ͨ¸æ

2020-08-04 VSRCÐû²¼Îó²îͨ¸æ


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨