Third Party Index

Snapshot 25492

Document
Security advisories
URL
https://community.sonarsource.com/t/responsible-vulnerability-disclosure/9317
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
browser
Size
635580 bytes
SHA-256 (raw)
28b3c65c4361155ee8cdda5a98ab31b20178fe855b9384d5e5160ca9709a6190
SHA-256 (normalized text)
6bd7ba061816bafa1c3f0ade06a72b138818433b1b1c72d4ebe9fdbcfae48020

Normalized text

Scripts and page chrome removed; this is what change detection compares.

The next Sonar developer survey is open and calling for responses! Take the survey
Responsible Vulnerability Disclosure
Sonar UpdatesGuides
security
You have selected 0 posts.
select all
cancel selecting
3
May 2019
1 / 8
May 2019
8d ago
post by Alexandre_Gigleux on May 2, 2019
Alexandre Gigleux Product Manager
Follow this guide if you’ve found a vulnerability in one of Sonar’s products or websites and you want to responsibly report it.
Sonar customers with a support contract can report the vulnerability directly through the support channel.
Otherwise, send an email to [email protected].
What we need from you:
Detail the steps you followed that make the vulnerability exploitable including any URLs or code you used. The more information you provide, the faster we can reproduce and fix the problem.
Please don’t send PDF, DOC, or EXE files or reports generated by DAST products. We will not look at them. We do accept images.
Focus areas:
Cross-site scripting (XSS)
SQL injection (SQLi)
Cross-site request forgery (CSRF)
Remote code execution (RCE)
Cookies not used for authentication or CSRF protection, not being marked as Secure or HTTPOnly
Data breaches, such as data of private projects or private organizations on SonarQube Cloud.
Out of scope:
Findings that require the attacker to already hold the highest available administrator/owner privileges on their own instance or organization, where the effect is confined to that same instance/organization and results only in the admin gaining functionality gated by a different license tier or edition (e.g., bypassing a per-edition feature limit via timing/race conditions). These are licensing/entitlement issues, not security vulnerabilities, and should be reported to your account team instead.
This exclusion does not apply if the technique can affect another organization, tenant, or user’s data or availability, or if it is achievable by a role below the top-level admin; either of those makes it an access-control issue and keeps it in scope."
How SonarSource rewards you?
It’s in our plans, but we don’t have a bug bounty program currently. Instead, if you accept it, we’ll put you in the Hall of Fame section of this guide under the name or nickname of your choice.
Public disclosure
You need to get our permission before disclosing an issue publicly. We’ll only consider your public disclosure request after we’ve fixed the reported vulnerability.
Hall of Fame
Thank you all for having reported vulnerabilities privately, you rock!
Francois Lajeunesse-Robert
Ethiack
Moti Harmats and Sharon Brizinov
NH Limon
Sujal Tuladhar and Pradip Bhattarai
Ali Haider
Nils Jannasch
Clément Amic and Hugo Vincent
Dhane Ashley Diabajo
Nikolas Sotiriu
Wesley Kirkland
Sebastien Copin
Gia. Bui Dai
dcRUSTy
Vaibhav Atkale
Armanul Miraz
Harsh D Ranjan
Saurabh Siddharam Sanmane
Alisha Sheikh
Keitaro Yamazaki
Pritam Mukherjee
Amiya Behera
Avishek Nayal
SureshkumarAnbazhagan
Suhas Sainathan
Hassan Shahid
Umesh P Jore
Rayen Messaoudi
Pethuraj M
Vault Infosec
Vo Phu Vinh
XSS Attack Prevention
How can i report security bug and a CVE(Common Vulnerabilities and Exposures) for sonarqube application, whats the procedure
How to report a SonarQube security vulnerability?
Issues with generating PDF Report from the portfolio
H2 Database Console Remote Code Execution [Severity: Critical]
3
25 days later
post by farnulfo on May 27, 2019
post by Alexandre_Gigleux on May 27, 2019
2 months later
post by Alexandre_Gigleux on Jul 23, 2019
4 months later
post by simon.brandhof on Nov 18, 2019
4 years later
post by hilari0n on Apr 26, 2024
27 days later
post by Joe on May 24, 2024
2 years later
post by LouisDeconinck on Sep 23
Related topics
Topic list, column headers with buttons are sortable.
Topic	Replies	Views	Activity
How to report a SonarQube security vulnerability?
SonarQube Server / Community Build
1	1.2k	May 2021
How can i report security bug and a CVE(Common Vulnerabilities and Exposures) for sonarqube application, whats the procedure
SonarQube Server / Community Build
1	1.4k	Dec 2020
XSS Attack Prevention
SonarQube Server / Community Build
5	2.3k	May 2019
Vulnerability Disclosure Info
SonarQube Server / Community Build
1	751	Aug 2018
Vulnerability in Confluence version
SonarQube Server / Community Build
documentation
2	789	Apr 2019
Sonar Solutions
SAST
AI solutions
DevOps transformation
Outsourcing software development
Reduce & manage technical debt
Secure by design
Code coverage
Code review
For developers
For enterprise
Infrastructure as Code
Public sector
Products
SonarQube for IDE
SonarQube Server
SonarQube Cloud
Company
About
Careers
Commitment to open source
Customers
Partners
Contact us
Accessibility
Brand Identity
Media
Coverage
Press releases
Resources
Product Demos
Events Hub
Customer stories
White papers
Learn
Community
Support
Legal Documentation
Knowledge
Explore Sonar's Rules
Blog
Languages
SonarQube Server Documentation
SonarQube Cloud Documentation
SonarQube for IDE Documentation
Pricing
Start for free
Explore pricing
© 2025 SonarSource Sàrl. All rights reserved.