CVE-2025-62292
BaseFortify
Publication date: 2025-10-10
Last updated on: 2025-10-14
Assigner: MITRE
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| sonarsource | sonarqube | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-669 | The product does not properly transfer a resource/behavior to another sphere, or improperly imports a resource/behavior from another sphere, in a manner that provides unintended control over that resource. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability in SonarQube versions before 25.6, 2025.3 Commercial, and 2025.1.3 LTA allows authenticated users with low privileges to access the /api/v2/users-management/users endpoint and retrieve user information that should only be accessible to administrators, including the email addresses of other users.
How can this vulnerability impact me? :
The vulnerability can lead to unauthorized disclosure of user email addresses to low-privileged authenticated users, potentially exposing sensitive user information and increasing the risk of targeted phishing or social engineering attacks.