Skip to main content

Vendor/product archive

sonarsource / sonarqube CVEs

Beta · best-effort

7 CVEs tagged to sonarsource / sonarqube0 Critical, 1 High, 6 Medium, 0 Low, 0 Unrated.

CVE-2024-47911

Published Oct 4, 2024

In SonarSource SonarQube 10.4 through 10.5 before 10.6, a vulnerability was discovered in the authorizations/group-memberships API endpoint that allows SonarQube users with the ad…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-38460

Published Jun 16, 2024

In SonarQube before 10.4 and 9.9.4 LTA, encrypted values generated using the Settings Encryption feature are potentially exposed in cleartext as part of the URL parameters in the…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-28002

Published Nov 2, 2020

In SonarQube 8.4.2.36762, an external attacker can achieve authentication bypass through SonarScanner. With an empty value for the -D sonar.login option, anonymous authentication…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-27986

Published Oct 28, 2020

SonarQube 8.4.2.36762 allows remote attackers to discover cleartext SMTP, SVN, and GitLab credentials via the api/settings/values URI. NOTE: reportedly, the vendor's position for…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-19413

Published Dec 14, 2018

A vulnerability in the API of SonarSource SonarQube before 7.4 could allow an authenticated user to discover sensitive information such as valid user-account logins in the web app…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-7 of 7 CVEsPage 1 of 1