Input validation error in Nexus Repository Manager - CVE-2020-10204
Published: April 2, 2020 / Updated: June 3, 2020
Vulnerability identifier: #VU26535
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-10204
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
Public exploit is available
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to insufficient validation of user-supplied input. A remote authenticated attacker can send a specially crafted request to NXRM and execute arbitrary code on the target system.
Affected software
Nexus Repository Manager
How to mitigate CVE-2020-10204
Install updates from vendor's website.
Nexus Repository Manager - update to 3.21.2-03
Links to Public Exploits and PoC-codes
- Exploit #2907 - CVE-2020-10199-10204 (CVE-2020-10199 CVE-2020-10204 Python POC) (June 3, 2020)
- Exploit #2914 - CVE-2020-10199 (CVE-2020-10199、CVE-2020-10204、CVE-2020-11444) (June 3, 2020)
- Exploit #2920 - CVE-2020-10199_CVE-2020-10204 (CVE-2020-10199、CVE-2020-10204漏洞一键检测工具,图形化界面。CVE-2020-10199 and CVE-2020-10204 Vul Tool with GUI.) (June 3, 2020)
- Exploit #2933 - CVE-2020-10204 () (June 3, 2020)
- Exploit #3001 - CVE-2020-10204 (CVE-2020-10204 远程命令执行脚本) (June 3, 2020)