CVE-2024-47910
EUVD-2024-4272404.10.2024, 21:15
An issue was discovered in SonarSource SonarQube before 9.9.5 LTA and 10.x before 10.5. A SonarQube user with the Administrator role can modify an existing configuration of a GitHub integration to exfiltrate a pre-signed JWT.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| sonarsource | sonarqube | 10.0 ≤ 𝑥 < 10.5 | ADP |
| sonarsource | sonarqube | 𝑥 < 9.9.5lta | ADP |
Common Weakness Enumeration