CVE-2024-47910: Sonarsource Sonarqube

High severity, CVSS 7.2. EPSS: 0.5% chance of exploitation in the next 30 days.

An issue was discovered in SonarSource SonarQube before 9.9.5 LTA and 10.x before 10.5. A SonarQube user with the Administrator role can modify an existing configuration of a GitHub integration to exfiltrate a pre-signed JWT.

Affected products

  • Sonarsource Sonarqube: from 10.0, before 10.5 (fixed in 10.5); before 9.9.5lta (fixed in 9.9.5lta)

Published 2024-10-04. Last modified 2026-06-17.