SonarSource SonarQube
cpe:2.3:a:sonarsource:sonarqube:*:*:*:*:*:*:*
- < 9.9.5 LTA
- >= 10, < 10.5
A vulnerability exists in SonarSource SonarQube versions prior to 9.9.5 LTA and 10.x prior to 10.5. Users with the Administrator role can alter GitHub integration settings to exfiltrate a pre-signed JSON Web Token (JWT).
Exploitation of this vulnerability leads to unauthorized information disclosure by allowing the extraction of a pre-signed JWT, which could potentially be misused in the context of the application's authentication or authorization processes.
Users can upgrade to SonarQube versions 9.9.5 LTA or 10.5 and later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.