4.3
CVE-2025-62292
- EPSS 0.05%
- Veröffentlicht 10.10.2025 00:00:00
- Zuletzt bearbeitet 14.10.2025 19:37:28
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
In SonarQube before 25.6, 2025.3 Commercial, and 2025.1.3 LTA, authenticated low-privileged users can query the /api/v2/users-management/users endpoint and obtain user fields intended for administrators only, including the email addresses of other accounts.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerSonarSource
≫
Produkt
SonarQube
Default Statusunaffected
Version <
25.6 Community
Version
10.2 Community
Status
affected
Version <
2025.3 Commercial
Version
10.2 Commercial
Status
affected
Version <
2025.1.3 LTA
Version
2025.1 LTA
Status
affected
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.05% | 0.153 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| cve@mitre.org | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|
CWE-669 Incorrect Resource Transfer Between Spheres
The product does not properly transfer a resource/behavior to another sphere, or improperly imports a resource/behavior from another sphere, in a manner that provides unintended control over that resource.