Vulnerability index

Browse CVEs

7 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.2 CVE-2024-47911 In SonarSource SonarQube 10.4 through 10.5 before 10.6, a vulnerability was discovered in the authorizations/group-memberships API endpoint that allo… Sonarqube 10.6+ Fix from $1,9502024-10-04 MEDIUM 6.5 CVE-2024-38460 In SonarQube before 10.4 and 9.9.4 LTA, encrypted values generated using the Settings Encryption feature are potentially exposed in cleartext as part… Sonarqube 9.9.4 / 10.4+ Fix from $1,6002024-06-16 CRITICAL 9.8 CVE-2020-35193 The official sonarqube docker images before alpine (Alpine specific) contain a blank password for a root user. System using the sonarqube docker cont… Sonarqube Docker Image Mitigation only Fix from $2,3002020-12-16 MEDIUM 5.3 CVE-2020-28002 In SonarQube 8.4.2.36762, an external attacker can achieve authentication bypass through SonarScanner. With an empty value for the -D sonar.login opt… Sonarqube No fix yet Fix from $1,6002020-11-02 HIGH 7.5 CVE-2020-27986EPSS 16% SonarQube 8.4.2.36762 allows remote attackers to discover cleartext SMTP, SVN, and GitLab credentials via the api/settings/values URI. NOTE: reported… Sonarqube Mitigation only Fix from $1,9502020-10-28 MEDIUM 6.1 CVE-2019-17579 SonarSource SonarQube before 7.8 has XSS in project links on account/projects. Sonarqube 7.8+ Fix from $1,6002019-10-14 HIGH 7.8 CVE-2018-1000425 An insufficiently protected credentials vulnerability exists in Jenkins SonarQube Scanner Plugin 2.8 and earlier in SonarInstallation.java that allow… Sonarqube Scanner after 2.8 Fix from $1,9502019-01-09