Nexus Repository Manager 3 Ô¶³Ì´úÂëÖ´Ðзì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-02-14

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-7238£¬£¬£¬£¬£¬ £¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬ £¬ CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°ÏìÁìÓò


ÊÜÓ°Ïì°æ±¾£º 

Nexus Repository Manager OSS/Pro 3.x < 3.15


·ì϶¸ÅÊö


2019Äê2ÔÂ5ÈÕ£¬£¬£¬£¬£¬ £¬Sonatype ¹Ù·½°ä²¼°²È«¹«¸æ£¬£¬£¬£¬£¬ £¬½¨¸´ÁË´æÔÚÓÚ Nexus Repository Manager 3ÖеÄÒ»¸öÔ¶³Ì´úÂëÖ´Ðзì϶¡£¡£ ¡£¡£¡£¡£


Sonatype NexusÊÇÒ»¸öMavenµÄ²Ö¿âÖÎÀíϵͳ£¬£¬£¬£¬£¬ £¬ËüÌṩÁË׳´óµÄ²Ö¿âÖÎÀí¡¢¹¹¼þËÑË÷µÈÖ°ÄÜ£¬£¬£¬£¬£¬ £¬²¢ÇÒÄܹ»ÓÃÀ´´î½¨Maven²Ö¿â˽·þ£¬£¬£¬£¬£¬ £¬ÔÚ´úÀíÔ¶³Ì²Ö¿âµÄÍ¬Ê±ÊØ»¤±¾µØ²Ö¿â£¬£¬£¬£¬£¬ £¬ÒÔ½Ú¼ó´ø¿íºÍ¹¦·ò¡£¡£ ¡£¡£¡£¡£


ÔÚNexus Repository Manager OSS/Pro 3.15֮ǰµÄ°æ±¾ÖУ¬£¬£¬£¬£¬ £¬ÓÉÓÚij´¦Ö°Äܲ»×ã½Ó¼û½ÚÔ죬£¬£¬£¬£¬ £¬ÇÒδÄÜÕýÈ·´¦ÖÃÓû§´«ÈëµÄÊý¾Ý£¬£¬£¬£¬£¬ £¬µ¼ÖÂÔ¶³ÌÇÒδ¾­ÊÚȨÈÏÖ¤µÄ¹¥»÷Õߣ¬£¬£¬£¬£¬ £¬½öͨ¹ýÒ»¸ö¶ñÒâµÄ HTTPÒªÇ󣬣¬£¬£¬£¬ £¬¾ÍÄܹ»ÔÚ·þÎñ¶ËÖ´ÐÐËÁÒâJava´úÂ룬£¬£¬£¬£¬ £¬»ñȡϵͳȨÏÞ£º


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website



Ŀǰ¹Ù·½ÒѾ­Í¨¹ýÔö³¤½Ó¼û½ÚÔì´ëÊ©ºÍ½ûÓ÷þÎñÆ÷ÉÏÌØ¶¨õè¾¶µÄJava´úÂëÖ´ÐÐÄÜÁ¦À´»º½â¸Ã·ì϶¡£¡£ ¡£¡£¡£¡£


½¨¸´½¨Òé


Ŀǰ¹Ù·½ÒѾ­°ä²¼Ð°汾Åú¸ÄÁ˸÷ì϶£¬£¬£¬£¬£¬ £¬ÇëÉý¼¶ Nexus Repository Manager OSS/Pro 3 µ½ 3.15 °æ±¾¡£¡£ ¡£¡£¡£¡£ÏÂÔØÁ´½Ó£ºhttps://help.sonatype.com/repomanager3/download¡£¡£ ¡£¡£¡£¡£


²Î¿¼Á´½Ó


https://support.sonatype.com/hc/en-us/articles/360017310793-CVE-2019-7238-Nexus-Repository-Manager-3-Missing-Access-Controls-and-Remote-Code-Execution-February-5th-2019