IQ Server vulnerable to Path Traversal attack
CVE-2024-1142

5.4MEDIUM

Key Information:

Vendor

Sonatype

Status
Vendor
CVE Published:
21 March 2024

What is CVE-2024-1142?

The Path Traversal vulnerability in Sonatype IQ Server enables remote authenticated attackers to exploit the system by crafting specific requests. This flaw allows for unauthorized file overwriting or deletion, which poses significant risks to system security and data integrity. Users are advised to upgrade to version 171, which addresses this critical issue and enhances overall protection.

Affected Version(s)

IQ Server 143 < 171

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.