Showing 4 vulnerabilities on this page for sonarqube

Signals CISA KEV Ransomware Nuclei
SonarSource vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

In SonarQube before 25.6, 2025.3 Commercial, and 2025.1.3 LTA, authenticated low-privileged users can query the /api/v2/users-management/users endpoint and obtain user fields intended for administrators only, including the email addresses of other accounts.

CWE-669Oct 10, 2025
CVSS4.3v3.1EPSS0.209%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

In SonarSource SonarQube 10.4 through 10.5 before 10.6, a vulnerability was discovered in the authorizations/group-memberships API endpoint that allows SonarQube users with the administrator role to inject blind SQL commands.

CWE-89Oct 4, 2024
CVSS6.7v3.1EPSS0.451%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

An issue was discovered in SonarSource SonarQube before 9.9.5 LTA and 10.x before 10.5. A SonarQube user with the Administrator role can modify an existing configuration of a GitHub integration to exfiltrate a pre-signed JWT.

CWE-284Oct 4, 2024
CVSS7.2v3.1EPSS0.482%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

sonarsource sonarqube Missing Authentication for Critical Function

SonarQube 8.4.2.36762 allows remote attackers to discover cleartext SMTP, SVN, and GitLab credentials via the api/settings/values URI. NOTE: reportedly, the vendor's position for SMTP and SVN is "it is the administrator's responsibility to configure it.

CWE-306CWE-312CWE-522Oct 28, 20201 related artifact
CVSS7.5v3.1EPSS16.4%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX