VYPR

Maven package

org.sonarsource.sonarqube/sonar-web

pkg:maven/org.sonarsource.sonarqube/sonar-web

Vulnerabilities (1)

  • CVE-2024-38460Jun 16, 2024
    affected < 9.9.4fixed 9.9.4

    In SonarQube before 10.4 and 9.9.4 LTA, encrypted values generated using the Settings Encryption feature are potentially exposed in cleartext as part of the URL parameters in the logs (such as SonarQube Access Logs, Proxy Logs, etc).