Nexus Repository Manager OSS 3.14.0, vulnerable to CVE-2019-7238: the coreui_Component getPreviousUsage call evaluates the jexlExpression of a content selector without authentication, which runs Java code once the repository holds at least one component.
Pas commencéDockercommit 8b95301x86_64 · aarch64Secret
Exploit CVE-2019-7238 to run commands on the Nexus server and get a shell.
Le brief de ce lab se trouve dans son dépôt.