CVE-2019-5475

HIGH8.8EPSS 79.6%

OS Command Injection in Nexus Yum Repository Plugin

發布日:2019/9/11修改日:2023/11/8

描述

The Nexus Yum Repository Plugin in v2 is vulnerable to Remote Code Execution when instances using CommandLineExecutor.java are supplied vulnerable data, such as the Yum Configuration Capability.

受影響套件(1)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1HIGH8.8CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

參考連結(2)