CVE-2024-38460

Severity CVSS v4.0:
Pending analysis
Type:
CWE-532 Information Exposure Through Log Files
Publication date:
16/06/2024
Last modified:
13/03/2025

Description

In SonarQube before 10.4 and 9.9.4 LTA, encrypted values generated using the Settings Encryption feature are potentially exposed in cleartext as part of the URL parameters in the logs (such as SonarQube Access Logs, Proxy Logs, etc).

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sonarsource:sonarqube:*:*:*:*:*:*:*:* 9.9.4 (excluding)
cpe:2.3:a:sonarsource:sonarqube:*:*:*:*:*:*:*:* 10.0.0.68432 (including) 10.4 (excluding)