Vulnerability index

Browse CVEs

7 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Sonarqube HIGH 7.2
CVE-2024-47911

In SonarSource SonarQube 10.4 through 10.5 before 10.6, a vulnerability was discovered in the authorizations/group-memberships API endpoint that allo…

Fix: 10.6+
Fix from $1,950 2024-10-04
Sonarqube MEDIUM 6.5
CVE-2024-38460

In SonarQube before 10.4 and 9.9.4 LTA, encrypted values generated using the Settings Encryption feature are potentially exposed in cleartext as part…

Fix: 9.9.4 / 10.4+
Fix from $1,600 2024-06-16
Sonarqube Docker Image CRITICAL 9.8
CVE-2020-35193

The official sonarqube docker images before alpine (Alpine specific) contain a blank password for a root user. System using the sonarqube docker cont…

Mitigation only
Fix from $2,300 2020-12-16
Sonarqube MEDIUM 5.3
CVE-2020-28002

In SonarQube 8.4.2.36762, an external attacker can achieve authentication bypass through SonarScanner. With an empty value for the -D sonar.login opt…

No fix yet
Fix from $1,600 2020-11-02
Sonarqube HIGH 7.5
CVE-2020-27986EPSS 16%

SonarQube 8.4.2.36762 allows remote attackers to discover cleartext SMTP, SVN, and GitLab credentials via the api/settings/values URI. NOTE: reported…

Mitigation only
Fix from $1,950 2020-10-28
Sonarqube MEDIUM 6.1
CVE-2019-17579

SonarSource SonarQube before 7.8 has XSS in project links on account/projects.

Fix: 7.8+
Fix from $1,600 2019-10-14
Sonarqube Scanner HIGH 7.8
CVE-2018-1000425

An insufficiently protected credentials vulnerability exists in Jenkins SonarQube Scanner Plugin 2.8 and earlier in SonarInstallation.java that allow…

Fix: after 2.8
Fix from $1,950 2019-01-09