๐Ÿ” CVE Alert

CVE-2024-47910

HIGH 7.2
CVSS Score
7.2
EPSS Score
0.0%
EPSS Percentile
0th

An issue was discovered in SonarSource SonarQube before 9.9.5 LTA and 10.x before 10.5. A SonarQube user with the Administrator role can modify an existing configuration of a GitHub integration to exfiltrate a pre-signed JWT.

Vendor n/a
Product n/a
Published Oct 4, 2024
Last Updated Oct 4, 2024
Stay Ahead of the Next One

Get instant alerts for n/a n/a

Be the first to know when new high vulnerabilities affecting n/a n/a are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

n/a / n/a
n/a

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
sonarsource.atlassian.net: https://sonarsource.atlassian.net/browse/SONAR-21795 sonarsource.atlassian.net: https://sonarsource.atlassian.net/browse/SONAR-21813 community.sonarsource.com: https://community.sonarsource.com/t/sonarqube-github-integration-information-leakage/126609