CVE-2024-47911

CVSS 3.1 Score 6.7 of 10 (medium)

Details

Published Oct 4, 2024
Updated: Oct 7, 2024
CWE ID 89

Summary

CVE-2024-47911 identifies a vulnerability in SonarSource SonarQube versions 10.4 through 10.5, specifically within the authorizations/group-memberships API endpoint. This security flaw allows users with administrator privileges to execute blind SQL injection attacks, which can compromise both the integrity and confidentiality of data. Affected products include SonarQube installations in the specified versions, and remediation involves upgrading to version 10.6 or later to mitigate this risk. The vulnerability has a medium severity rating with a CVSS base score of 6.7, indicating potential high impact on organizations that do not address it promptly. Exploitation requires high privileges but does not necessitate user interaction, making it particularly concerning for networked environments.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share