Maven拉取Artifact遇Access denied:Forbidden问题求助
解决Maven访问Nexus获取plexus-interpolation依赖时的403 Forbidden问题
问题背景
在大型企业环境中使用Maven构建应用时,所有依赖/插件均通过Sonatype Nexus代理或托管,但执行mvn clean install时出现以下错误:
[ERROR] Failed to execute goal org.apache.maven.plugins:maven-resources-plugin:3.3.1:resources (default-resources) on project <redacted>: Execution default-resources of goal org.apache.maven.plugins:maven-resources-plugin:3.3.1:resources failed: Plugin org.apache.maven.plugins:maven-resources-plugin:3.3.1 or one of its dependencies could not be resolved: Failed to collect dependencies at org.apache.maven.plugins:maven-resources-plugin:jar:3.3.1 -> org.codehaus.plexus:plexus-interpolation:jar:1.26: Failed to read artifact descriptor for org.codehaus.plexus:plexus-interpolation:jar:1.26: Could not transfer artifact org.codehaus.plexus:plexus-interpolation:pom:1.26 from/to nexus (http://<redacted.tld>/repository/maven/): Access denied to: http://<redacted.tld>/repository/maven/org/codehaus/plexus/plexus-interpolation/1.26/plexus-interpolation-1.26.pom , ReasonPhrase:Forbidden. -> [Help 1]
已知前提:
- Nexus团队确认仓库支持匿名访问,无需登录
- 通过Nexus UI获取的链接用
wget可正常下载该POM文件 - 项目其他依赖能正常下载,代理配置整体有效
- 环境信息:Amazon Linux 2(AWS EC2)、Maven 3.5.2、Coretto 17.0.8 LTS、Nexus Repository Pro 3.44.0
解决思路
1. 模拟wget的用户代理请求
Maven默认的HTTP用户代理为Apache Maven/<版本> Java/<版本>,部分企业Nexus可能对特定用户代理做了访问限制。可以临时修改Maven的用户代理来测试:
命令行临时指定:
mvn clean install -Dhttp.agent="Wget/1.14 (linux-gnu)"
或者在~/.m2/settings.xml中永久配置(已有代理配置则添加userAgent节点):
<settings> <proxies> <proxy> <userAgent>Wget/1.14 (linux-gnu)</userAgent> </proxy> </proxies> </settings>
2. 核对Maven使用的Nexus URL与wget一致
检查~/.m2/settings.xml中的镜像配置,确保指向的Nexus仓库URL和wget使用的完全匹配(包括末尾斜杠、HTTP/HTTPS协议):
<mirrors> <mirror> <id>nexus</id> <mirrorOf>*</mirrorOf> <url>http://<redacted.tld>/repository/maven/</url> </mirror> </mirrors>
细微的URL差异可能触发Nexus的权限拦截规则。
3. 排查Nexus仓库的配置细节
- 确认该依赖所在的代理仓库(如maven-central)已被包含在你使用的仓库组中,仓库组的成员列表可能遗漏了对应源
- 在Nexus UI中找到
plexus-interpolation-1.26.pom的路径,手动触发重新代理(点击"Rebuild Metadata"或"Proxy Remote"按钮),可能存在缓存异常导致的权限问题 - 再次确认Nexus匿名用户对目标仓库/仓库组拥有读取权限,尤其是插件类依赖可能走单独的仓库配置,权限规则可能未覆盖
4. 验证Maven与Java版本的兼容性
Maven 3.5.2发布于2017年,与Java 17存在兼容性风险,可能导致HTTP请求处理异常:
- 临时切换到Java 8/11版本重新构建,看是否解决问题
- 升级Maven到3.8.x系列(对Java 17支持更完善)后重试构建
5. 清理Maven本地缓存
本地仓库可能存在损坏的缓存文件,导致重复请求失败:
rm -rf ~/.m2/repository/org/codehaus/plexus/plexus-interpolation/1.26
清理后重新执行mvn clean install,让Maven重新从Nexus拉取依赖。
6. 检查EC2实例的网络策略
AWS EC2的安全组、NACL或企业防火墙可能限制了Maven进程的出站请求:
- 对比wget和Maven的请求端口:wget用随机端口,Maven可能因JVM配置使用固定端口,检查该端口是否被允许访问Nexus
- 用
tcpdump抓包对比两者的HTTP请求头,看是否存在Cookie、Referer等差异导致Nexus拒绝访问
内容的提问来源于stack exchange,提问作者Codebaard
相关产品推荐
相关产品推荐

