logo
Vulnerability feed
CONTRIBUTE

Vulnerability

warn

CVE-2024-38460

Reference to the description:

https://nvd.nist.gov/vuln/detail/CVE-2024-38460

Description:
In SonarQube before 10.4 and 9.9.4 LTA, encrypted values generated using the Settings Encryption feature are potentially exposed in cleartext as part of the URL parameters in the logs (such as SonarQube Access Logs, Proxy Logs, etc).
Last updated date:
08/07/2024
Type:
exploit
Confidence:
HIGH
Date of publishing:
08/07/2024
Reference url to background

https://community.sonarsource.com/t/sonarqube-ce-10-3-0-leaking-encrypted-values-in-web-server-logs/108187

Vulnerability FeedContributorsAboutBlog

@inTheWild

©2024

Privacy Policy