Vulnerability Description
In SonarQube before 10.4 and 9.9.4 LTA, encrypted values generated using the Settings Encryption feature are potentially exposed in cleartext as part of the URL parameters in the logs (such as SonarQube Access Logs, Proxy Logs, etc).
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sonarsource | Sonarqube | < 9.9.4 |
Related Weaknesses (CWE)
References
- https://community.sonarsource.com/t/sonarqube-ce-10-3-0-leaking-encrypted-valuesExploitIssue TrackingVendor Advisory
- https://sonarsource.atlassian.net/browse/SONAR-21559Issue Tracking
- https://community.sonarsource.com/t/sonarqube-ce-10-3-0-leaking-encrypted-valuesExploitIssue TrackingVendor Advisory
- https://sonarsource.atlassian.net/browse/SONAR-21559Issue Tracking
FAQ
What is CVE-2024-38460?
CVE-2024-38460 is a vulnerability with a CVSS score of 4.9 (MEDIUM). In SonarQube before 10.4 and 9.9.4 LTA, encrypted values generated using the Settings Encryption feature are potentially exposed in cleartext as part of the URL parameters in the logs (such as SonarQu...
How severe is CVE-2024-38460?
CVE-2024-38460 has been rated MEDIUM with a CVSS base score of 4.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-38460?
Check the references section above for vendor advisories and patch information. Affected products include: Sonarsource Sonarqube.