Description
Sonatype Nexus Repository 3.x through 3.33.1-01 is vulnerable to an HTTP header injection. By sending a crafted HTTP request, a remote attacker may disclose sensitive information or request external resources from a vulnerable instance.
Remediation
References
https://issues.sonatype.org/secure/ReleaseNote.jspa
https://support.sonatype.com/hc/en-us/articles/4405941762579
Related Vulnerabilities
CVE-2016-0762 Vulnerability in maven package org.apache.tomcat:catalina
CVE-2021-41411 Vulnerability in maven package org.drools:drools-core
CVE-2021-23369 Vulnerability in npm package handlebars
CVE-2016-6497 Vulnerability in maven package org.xbib.groovy:groovy-ldap
CVE-2016-6796 Vulnerability in maven package tomcat:jasper-compiler