CVE-2021-40143: High severity Sonatype Nexus Repository Manager 3 vulnerability
Published Sep 7, 2021
·Updated
Sonatype Nexus Repository 3.x through 3.33.1-01 is vulnerable to an HTTP header injection. By sending a crafted HTTP request, a remote attacker may disclose sensitive information or request external resources from a vulnerable instance.
Affected Software
1 affected component
Sonatype Nexus Repository Manager 3>=3.0.0<3.34.0
Remediation
Patch Available
Event History
Sep 7, 2021
CVE Published
via MITRE·07:28 PM
Data Sourced
via MITRE·07:28 PM
Description
Data Sourced
via NVD·08:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-40143.
2
What is the severity of CVE-2021-40143?
CVE-2021-40143 has a severity rating of 8.2 (High).
3
Which software is affected by CVE-2021-40143?
Sonatype Nexus Repository 3.x through 3.33.1-01 is affected by CVE-2021-40143.
4
What is the impact of CVE-2021-40143?
CVE-2021-40143 allows a remote attacker to disclose sensitive information or request external resources from a vulnerable instance.
5
How can I fix CVE-2021-40143?
To fix CVE-2021-40143, upgrade Sonatype Nexus Repository to version 3.34.0 or newer.