CVE-2024-1142: Sonatype Iq Server

Medium severity, CVSS 5.4. EPSS: 0.8% chance of exploitation in the next 30 days.

Path Traversal in Sonatype IQ Server from version 143 allows remote authenticated attackers to overwrite or delete files via a specially crafted request. Version 171 fixes this issue.

Affected products

  • Sonatype Iq Server: from 143, before 171 (fixed in 171)

Published 2024-03-21. Last modified 2026-06-17.