Back to Database
Status published
Medium
CVE-2024-1142
Sonatype IQ Server - Path Traversal
Vulnerability Description
Path Traversal in Sonatype IQ Server from version 143 allows remote authenticated attackers to overwrite or delete files via a specially crafted request. Version 171 fixes this issue.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-1142
Credits & Attribution
No credits recorded in the NVD database.
More from Sonatype
View All →CVE-2025-9868
Nexus Repository 2 - SSRF Vulnerability in Remote Browser Plugin
High
8.7
CVE-2025-13488
Nexus Repository 3 - Stored Cross-Site Scripting (XSS)
Medium
5.1
CVE-2024-5764
Nexus Repository 3 - Static hard-coded encryption passphrase used by default
Medium
5.9
CVE-2024-5083
Nexus Repository 2 - Stored XSS
Medium
5.1
CVE-2024-5082
Nexus Repository 2 - Remote Code Execution
High
7.1
Affected Vendor
Sonatype
View all reports →Affected Software
IQ Server
Vulnerable Versions:
143
Timeline
Official Publish:
March 6th, 2024
Last Modified:
August 5th, 2024
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L