Product
sonarsource sonarqube
6 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2024-47911
CVE-2024-38460
CVE-2020-28002
CVE-2020-27986
CVE-2019-17579
CVE-2018-19413
>= 10.4 and < 10.6
In SonarSource SonarQube 10.4 through 10.5 before 10.6, a vulnerability was discovered in the authorizations/group-memberships API
< 9.9.4
In SonarQube before 10.4 and 9.9.4 LTA, encrypted values generated using the Settings Encryption feature are potentially exposed i
all versions
In SonarQube 8.4.2.36762, an external attacker can achieve authentication bypass through SonarScanner. With an empty value for the
all versions
SonarQube 8.4.2.36762 allows remote attackers to discover cleartext SMTP, SVN, and GitLab credentials via the api/settings/values
< 7.8
SonarSource SonarQube before 7.8 has XSS in project links on account/projects.
< 7.4
A vulnerability in the API of SonarSource SonarQube before 7.4 could allow an authenticated user to discover sensitive information