RULE(RULE ID:335309)

Rule General Information
Release Date: 2024-11-25
Rule Name: Nexus Yum Repository Plugin Command Execution Vulnerability (CVE-2019-5475)
Severity:
CVE ID:
Rule Protection Details
Description: The Nexus Yum Repository Plugin in v2 is vulnerable to Remote Code Execution when instances using CommandLineExecutor.java are supplied vulnerable data, such as the Yum Configuration Capability.
Impact: An attacker can execute arbitrary command via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Linux, Others
Reference: https://hackerone.com/reports/654888
Solutions
The vendor has released upgrade patches to fix vulnerabilities, please visit:
https://support.sonatype.com/hc/en-us/articles/360033490774-CVE-2019-5475-Nexus-Repository-Manager-2-OS-Command-Injection-2019-08-09