cve/2024/CVE-2024-1142.md

18 lines
848 B
Markdown
Raw Permalink Normal View History

2024-05-25 21:48:12 +02:00
### [CVE-2024-1142](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-1142)
![](https://img.shields.io/static/v1?label=Product&message=IQ%20Server&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=143%3C%20171%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-22%20Improper%20Limitation%20of%20a%20Pathname%20to%20a%20Restricted%20Directory%20('Path%20Traversal')&color=brighgreen)
### Description
Path Traversal in Sonatype IQ Server from version 143 allows remote authenticated attackers to overwrite or delete files via a specially crafted request. Version 171 fixes this issue.
### POC
#### Reference
- https://support.sonatype.com/hc/en-us/articles/27034479038739-CVE-2024-1142-Sonatype-IQ-Server-Path-Traversal-2024-03-06
#### Github
No PoCs found on GitHub currently.