CVE-2024-38460: Sonarsource Sonarqube

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

In SonarQube before 10.4 and 9.9.4 LTA, encrypted values generated using the Settings Encryption feature are potentially exposed in cleartext as part of the URL parameters in the logs (such as SonarQube Access Logs, Proxy Logs, etc).

Affected products

  • Sonarsource Sonarqube: before 9.9.4 (fixed in 9.9.4); from 10.0.0.68432, before 10.4 (fixed in 10.4)

Published 2024-06-16. Last modified 2026-06-17.