ZeroHour

CVE-2024-38460

PoC
CVSS 3.1
6.5 medium
EPSS
<1%p26
Published
()
Modified
Description

In SonarQube before 10.4 and 9.9.4 LTA, encrypted values generated using the Settings Encryption feature are potentially exposed in cleartext as part of the URL parameters in the logs (such as SonarQube Access Logs, Proxy Logs, etc).

Vendors
sonarsource
Products
sonarqube
Weakness
CWE-532
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.