Nexus Repository Manger group 后台远程命令执行 CVE-2020-10199

漏洞描述

Nexus 后台存在一处任意EL表达式注入漏洞,只需要任意一个用户权限即可

漏洞影响

Note

Nexus < 3.21.1

环境搭建

https://github.com/vulhub/vulhub/tree/master/nexus/CVE-2020-10199

FOFA

Note

app="Nexus-Repository-Manager"

漏洞复现

漏洞触发需要任意账户权限

登录任意用户后修改 NXSESSIONID,发送请求包

Last updated

Was this helpful?