CVE-2020-15871 | Nexus Repository ManagerÔ¶³Ì´úÂëÖ´ÐÐÎó²îͨ¸æ

Ðû²¼Ê±¼ä 2020-08-04

0x00 Îó²î¸ÅÊö


CVE   ID

CVE-2020-15871

ʱ    ¼ä

2020-08-04

Àà   ÐÍ

RCE

µÈ    ¼¶

ÑÏÖØ

Ô¶³ÌʹÓÃ

ÊÇ

Ó°Ïì¹æÄ£

Nexus Repository Manager 3 OSS / Pro <= 3.25.0


0x01 Îó²îÏêÇé


ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾


2020Äê7ÔÂ29ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬SonatypeÐû²¼Ç徲ͨ¸æ£¬£¬£¬£¬£¬£¬£¬£¬ÐÞ¸´ÁËÒ»¸öNexus Repository Manager 3 Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-15871£©¡£¡£¡£¡£¡£¡£¡£¡£Æ¾Ö¤Sonatype¹ÙÍøµÄÐÎòÓÐÊʵ±È¨Ï޵Ĺ¥»÷Õß¿ÉʹÓøÃÎó²îÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£¡£

Sonatype Nexus Repository Manager£¨NXRM£©ÊÇÃÀ¹úSonatype¹«Ë¾µÄÒ»¿îMaven¿ÍÕ»ÖÎÀíÆ÷£¬£¬£¬£¬£¬£¬£¬£¬ËüÖ÷ÒªÓÃÓÚ¿ÍÕ»ÖÎÀíºÍËÑË÷µÈ¹¦Ð§¡£¡£¡£¡£¡£¡£¡£¡£

ƾ֤ÏÖÔÚFOFAϵͳ×îÐÂͳ¼ÆÊý¾Ý£¬£¬£¬£¬£¬£¬£¬£¬ÏÔʾȫÇò¹æÄ£ÄÚ£¨app="Nexus-Repository-Manager"£©¹²ÓÐ27865¸öÏà¹ØÐ§ÀͶÔÍ⿪·Å¡£¡£¡£¡£¡£¡£¡£¡£ÖйúʹÓÃÊýÄ¿×î¶à¹²ÓÐ13841¸ö£¬£¬£¬£¬£¬£¬£¬£¬ÃÀ¹úµÚ¶þ¹²ÓÐ5293¸ö£¬£¬£¬£¬£¬£¬£¬£¬µÂ¹úµÚÈý¹²ÓÐ2162¸ö¡£¡£¡£¡£¡£¡£¡£¡£


ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾


0x02 ´¦Öóͷ£½¨Òé


ÏÖÔÚ³§ÉÌÒÑÐû²¼Ð°汾3.25.1£¬£¬£¬£¬£¬£¬£¬£¬ÏÂÔØÁ´½Ó£º

https://help.sonatype.com/repomanager3/download

ÓйØÉý¼¶µÄÏêϸÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬£¬²Î¿¼ÒÔÏÂÁ´½Ó£º

https://support.sonatype.com/hc/zh-CN/articles/115000350007


0x03 Ïà¹ØÐÂÎÅ


https://www.security-database.com/detail.php?alert=CVE-2020-15871


0x04 ²Î¿¼Á´½Ó


https://support.sonatype.com/hc/en-us/articles/360052192693-CVE-2020-15871-Nexus-Repository-Manager-3-Remote-Code-Execution-2020-07-29


0x05 ʱ¼äÏß


2020-07-29 SonatypeÐû²¼Ç徲ͨ¸æ

2020-08-04 VSRCÐû²¼Îó²îͨ¸æ


ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾