QID 980997

QID 980997: Java (maven) Security Update for org.sonatype.nexus:nexus-repository (GHSA-f34x-8pf6-qc9c)

Sonatype Nexus Repository 3.x through 3.33.1-01 is vulnerable to an HTTP header injection. By sending a crafted HTTP request, a remote attacker may disclose sensitive information or request external resources from a vulnerable instance.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as Critical - 8.2 severity.
  • CVSS V2 rated as High - 6.4 severity.
  • Solution
    Customers are advised to refer to GHSA-f34x-8pf6-qc9c for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 980997

    Software Advisories
    Advisory ID Software Component Link
    GHSA-f34x-8pf6-qc9c org.sonatype.nexus:nexus-repository URL Logo github.com/advisories/GHSA-f34x-8pf6-qc9c