Home
MEDIUM: 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NDefault status
unaffected
10.2 Community (custom) before 25.6 Community
affected
10.2 Commercial (custom) before 2025.3 Commercial
affected
2025.1 LTA (custom) before 2025.1.3 LTA
affected
Description
In SonarQube before 25.6, 2025.3 Commercial, and 2025.1.3 LTA, authenticated low-privileged users can query the /api/v2/users-management/users endpoint and obtain user fields intended for administrators only, including the email addresses of other accounts.
Problem types
CWE-669 Incorrect Resource Transfer Between Spheres
Product status
10.2 Community (custom) before 25.6 Community
10.2 Commercial (custom) before 2025.3 Commercial
2025.1 LTA (custom) before 2025.1.3 LTA
References
sonarsource.atlassian.net/browse/SONAR-24830