GHSA-f34x-8pf6-qc9c
Dashboard / Vulnerabilities / GHSA-f34x-8pf6-qc9c
Summary: HTTP header injection in Sonatype Nexus Repository
Details: Sonatype Nexus Repository 3.x through 3.33.1-01 is vulnerable to an HTTP header injection. By sending a crafted HTTP request, a remote attacker may disclose sensitive information or request external resources from a vulnerable instance.
References: https://nvd.nist.gov/vuln/detail/CVE-2021-40143, https://github.com/sonatype/nexus-public, https://help.sonatype.com/repomanager3/release-notes/2021-release-notes, https://issues.sonatype.org/secure/ReleaseNote.jspa, https://support.sonatype.com/hc/en-us/articles/4405941762579
Affected packages
Package
Name: org.sonatype.nexus:nexus-repository
Purl: pkg:maven/org.sonatype.nexus/nexus-repository
Affected ranges
Type: ECOSYSTEM
Events:
