# CVE-2024-26308 in commons-compress-1.21.jar

**URL:** <https://community.sonatype.com/t/cve-2024-26308-in-commons-compress-1-21-jar/12635>\
**Category:** Sonatype Nexus Repository\
**Created:** [May 27, 2024, 7:30am UTC](https://community.sonatype.com/t/cve-2024-26308-in-commons-compress-1-21-jar/12635 "2024-05-27T07:30:29Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![slv\_b](https://avatars.discourse-cdn.com/v4/letter/s/eada6e/32.png) [@slv\_b](https://community.sonatype.com/u/slv_b)\
**Post date:** [May 27, 2024, 7:30am UTC](https://community.sonatype.com/t/cve-2024-26308-in-commons-compress-1-21-jar/12635/1 "2024-05-27T07:30:30Z")

</div>

My information security team has pointed out the vulnerability CVE-2024-26308 in commons-compress-1.21.jar.  
The recommended version for use is 1.26.0.  
However the latest version of nexus uses /nexus-3.68.1-02/system/org/apache/commons/commons-compress/1.24.0/commons-compress-1.24.0.jar  
There are two questions

1. are there plans to migrate to a new version of commons-compress?
2. If not, is it possible to change the “bad” version of commons-compress to the “good” one yourself?
