4.3
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Description
In SonarQube before 25.6, 2025.3 Commercial, and 2025.1.3 LTA, authenticated low-privileged users can query the /api/v2/users-management/users endpoint and obtain user fields intended for administrators only, including the email addresses of other accounts.
Basic Information
ID
CVE-2025-62292
Source
mitre
Published
Oct 10, 2025 at 00:00
Modified
Oct 10, 2025 at 06:17
Affected Product
Vendor
SonarSource
Product
SonarQube
Version
10.2 Community
Affected Versions
SonarSource SonarQube 10.2 Community
SonarSource SonarQube 10.2 Commercial
SonarSource SonarQube 2025.1 LTA
SonarSource SonarQube 10.2 Commercial
SonarSource SonarQube 2025.1 LTA