Sonatype Nexus Repository Manager CVE-2019-7238 Remote Code Execution Vulnerability
BID:107441
Info
Sonatype Nexus Repository Manager CVE-2019-7238 Remote Code Execution Vulnerability
| Bugtraq ID: | 107441 |
| Class: | Access Validation Error |
| CVE: |
CVE-2019-7238 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 05 2019 12:00AM |
| Updated: | Feb 05 2019 12:00AM |
| Credit: | Rico @ Tencent Security Yunding Lab and voidfyoo @ Chaitin Tech |
| Vulnerable: |
Sonatype Nexus 3.9.0 Sonatype Nexus 3.8.0 Sonatype Nexus 3.7.1 Sonatype Nexus 3.7.0 Sonatype Nexus 3.6.2 Sonatype Nexus 3.14.0 Sonatype Nexus 3.13.0 Sonatype Nexus 3.12.1 Sonatype Nexus 3.12.0 Sonatype Nexus 3.11.0 Sonatype Nexus 3.10.0 |
| Not Vulnerable: |
Sonatype Nexus 3.15.0 |
Discussion
Sonatype Nexus Repository Manager CVE-2019-7238 Remote Code Execution Vulnerability
Sonatype Nexus Repository Manager is prone to a remote code execution vulnerability.
An attacker can exploit this issue to execute arbitrary code on the affected system.
Nexus Repository Manager versions 3.6.2 OSS/Pro through 3.14.0 are vulnerable.
Sonatype Nexus Repository Manager is prone to a remote code execution vulnerability.
An attacker can exploit this issue to execute arbitrary code on the affected system.
Nexus Repository Manager versions 3.6.2 OSS/Pro through 3.14.0 are vulnerable.
Exploit / POC
Sonatype Nexus Repository Manager CVE-2019-7238 Remote Code Execution Vulnerability
The researcher has created a proof-of-concept to demonstrate the issue. Please see the references for more information.
The researcher has created a proof-of-concept to demonstrate the issue. Please see the references for more information.
Solution / Fix
Sonatype Nexus Repository Manager CVE-2019-7238 Remote Code Execution Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.