PT-2025-41531 · Sonarqube · Sonarqube
Published
2025-10-10
·
Updated
2025-10-10
·
CVE-2025-62292
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
SonarQube versions prior to 25.6
SonarQube 2025.3 Commercial versions prior to 2025.3
SonarQube 2025.1.3 LTA versions prior to 2025.1.3
Description
Authenticated users with low privileges can access the
/api/v2/users-management/users endpoint to retrieve user information intended only for administrators, including the email addresses of other accounts. The issue occurs when querying this endpoint. The users variable is exposed to unauthorized access.Recommendations
Update SonarQube to version 25.6 or later.
Update SonarQube 2025.3 Commercial to version 2025.3 or later.
Update SonarQube 2025.1.3 LTA to version 2025.1.3 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sonarqube