Sonatype Nexus Repository Manager 2.x命令注入漏洞

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### Maven artifact groupId: org.sonatype.nexus.plugins artifactId: nexus-yum-repository-plugin version: 2.14.9-01 ### Vulnerability #### Vulnerability Description The Nexus Yum Repository Plugin is vulnerable to Remote Code Execution. All instances using CommandLineExecutor.java with user-supplied data is vulnerable, such as the Yum Configuration Capability. #### Additional Details Source File and Line Number: https://github.com/sonatype/nexus-public/blob/release-2.14.9-01/plugins/yum/nexus-yum-repository-plugin/src/main/java/org/sonatype/nexus/yum/internal/capabilities/YumCapability.java#L121 #### Steps To Reproduce: Navigate to "Capabilities" in Nexus Repository Manager. Edit or create a new Yum: Configuration capability Set path of "createrepo" or "mergerepo" to an OS command (e.g. C:\Windows\System32\calc.exe) The OS command should now have executed as the SYSTEM user. Note that in this case, Nexus appends --version to the OS command. The following HTTP request was used to...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息