In SonarQube before 10.4 and 9.9.4 LTA, encrypted values generated using the Settings Encryption feature are potentially exposed in cleartext as part of the URL parameters in the logs (such as SonarQube Access Logs, Proxy Logs, etc).
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-2078 | In SonarQube before 10.4 and 9.9.4 LTA, encrypted values generated using the Settings Encryption feature are potentially exposed in cleartext as part of the URL parameters in the logs (such as SonarQube Access Logs, Proxy Logs, etc). |
Github GHSA |
GHSA-hw2c-8xgw-mf57 | SonarQube logs sensitive information |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 13 Mar 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 07 Aug 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sonarsource
Sonarsource sonarqube |
|
| Weaknesses | CWE-532 | |
| CPEs | cpe:2.3:a:sonarsource:sonarqube:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Sonarsource
Sonarsource sonarqube |
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-03-13T14:12:15.939Z
Reserved: 2024-06-16T00:00:00.000Z
Link: CVE-2024-38460
Updated: 2024-08-02T04:12:24.743Z
Status : Modified
Published: 2024-06-16T15:15:51.910
Modified: 2025-03-13T15:15:45.890
Link: CVE-2024-38460
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA