Sonarsource
Sonarsource Sonarqube: vulnerabilidades y CVE
Sonarsource Sonarqube tiene 10 vulnerabilidades publicadas, 3 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE10
Últimos 12 meses3
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-84665 | Alta (8) | 0.41% | — | 2 sept 2026 | Jenkins SonarQube Scanner Plugin 2.18.3 and earlier does not limit URL schemes for the dashboard links it creates based on SonarQube scanner results, allowing the `javascript:` scheme, resulting in a stored cross-site… |
| CVE-2020-37020 | Alta (8.5) | 0.14% | — | 29 ene 2026 | SonarQube 8.3.1 contains an unquoted service path vulnerability that allows local attackers to gain SYSTEM privileges by exploiting the service executable path. Attackers can replace the wrapper.exe in the service path… |
| CVE-2025-62292 | Media (4.3) | 0.22% | — | 10 oct 2025 | In SonarQube before 25.6, 2025.3 Commercial, and 2025.1.3 LTA, authenticated low-privileged users can query the /api/v2/users-management/users endpoint and obtain user fields intended for administrators only, including… |
| CVE-2024-47911 | Alta (7.2) | 0.45% | — | 4 oct 2024 | In SonarSource SonarQube 10.4 through 10.5 before 10.6, a vulnerability was discovered in the authorizations/group-memberships API endpoint that allows SonarQube users with the administrator role to inject blind SQL… |
| CVE-2024-47910 | Alta (7.2) | 0.48% | — | 4 oct 2024 | An issue was discovered in SonarSource SonarQube before 9.9.5 LTA and 10.x before 10.5. A SonarQube user with the Administrator role can modify an existing configuration of a GitHub integration to exfiltrate a… |
| CVE-2024-38460 | Media (6.5) | 0.33% | — | 16 jun 2024 | In SonarQube before 10.4 and 9.9.4 LTA, encrypted values generated using the Settings Encryption feature are potentially exposed in cleartext as part of the URL parameters in the logs (such as SonarQube Access Logs,… |
| CVE-2020-28002 | Media (5.3) | 1.1% | — | 2 nov 2020 | In SonarQube 8.4.2.36762, an external attacker can achieve authentication bypass through SonarScanner. With an empty value for the -D sonar.login option, anonymous authentication is forced. This allows creating and… |
| CVE-2020-27986 | Alta (7.5) | 16% | — | 28 oct 2020 | SonarQube 8.4.2.36762 allows remote attackers to discover cleartext SMTP, SVN, and GitLab credentials via the api/settings/values URI. NOTE: reportedly, the vendor's position for SMTP and SVN is "it is the… |
| CVE-2019-17579 | Media (6.1) | 0.66% | — | 14 oct 2019 | SonarSource SonarQube before 7.8 has XSS in project links on account/projects. |
| CVE-2018-19413 | Media (4.3) | 1.1% | — | 14 dic 2018 | A vulnerability in the API of SonarSource SonarQube before 7.4 could allow an authenticated user to discover sensitive information such as valid user-account logins in the web application. The vulnerability occurs… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.