Snapshot 25492
Normalized text
Scripts and page chrome removed; this is what change detection compares.
The next Sonar developer survey is open and calling for responses! Take the survey Responsible Vulnerability Disclosure Sonar UpdatesGuides security You have selected 0 posts. select all cancel selecting 3 May 2019 1 / 8 May 2019 8d ago post by Alexandre_Gigleux on May 2, 2019 Alexandre Gigleux Product Manager Follow this guide if you’ve found a vulnerability in one of Sonar’s products or websites and you want to responsibly report it. Sonar customers with a support contract can report the vulnerability directly through the support channel. Otherwise, send an email to [email protected]. What we need from you: Detail the steps you followed that make the vulnerability exploitable including any URLs or code you used. The more information you provide, the faster we can reproduce and fix the problem. Please don’t send PDF, DOC, or EXE files or reports generated by DAST products. We will not look at them. We do accept images. Focus areas: Cross-site scripting (XSS) SQL injection (SQLi) Cross-site request forgery (CSRF) Remote code execution (RCE) Cookies not used for authentication or CSRF protection, not being marked as Secure or HTTPOnly Data breaches, such as data of private projects or private organizations on SonarQube Cloud. Out of scope: Findings that require the attacker to already hold the highest available administrator/owner privileges on their own instance or organization, where the effect is confined to that same instance/organization and results only in the admin gaining functionality gated by a different license tier or edition (e.g., bypassing a per-edition feature limit via timing/race conditions). These are licensing/entitlement issues, not security vulnerabilities, and should be reported to your account team instead. This exclusion does not apply if the technique can affect another organization, tenant, or user’s data or availability, or if it is achievable by a role below the top-level admin; either of those makes it an access-control issue and keeps it in scope." How SonarSource rewards you? It’s in our plans, but we don’t have a bug bounty program currently. Instead, if you accept it, we’ll put you in the Hall of Fame section of this guide under the name or nickname of your choice. Public disclosure You need to get our permission before disclosing an issue publicly. We’ll only consider your public disclosure request after we’ve fixed the reported vulnerability. Hall of Fame Thank you all for having reported vulnerabilities privately, you rock! Francois Lajeunesse-Robert Ethiack Moti Harmats and Sharon Brizinov NH Limon Sujal Tuladhar and Pradip Bhattarai Ali Haider Nils Jannasch Clément Amic and Hugo Vincent Dhane Ashley Diabajo Nikolas Sotiriu Wesley Kirkland Sebastien Copin Gia. Bui Dai dcRUSTy Vaibhav Atkale Armanul Miraz Harsh D Ranjan Saurabh Siddharam Sanmane Alisha Sheikh Keitaro Yamazaki Pritam Mukherjee Amiya Behera Avishek Nayal SureshkumarAnbazhagan Suhas Sainathan Hassan Shahid Umesh P Jore Rayen Messaoudi Pethuraj M Vault Infosec Vo Phu Vinh XSS Attack Prevention How can i report security bug and a CVE(Common Vulnerabilities and Exposures) for sonarqube application, whats the procedure How to report a SonarQube security vulnerability? Issues with generating PDF Report from the portfolio H2 Database Console Remote Code Execution [Severity: Critical] 3 25 days later post by farnulfo on May 27, 2019 post by Alexandre_Gigleux on May 27, 2019 2 months later post by Alexandre_Gigleux on Jul 23, 2019 4 months later post by simon.brandhof on Nov 18, 2019 4 years later post by hilari0n on Apr 26, 2024 27 days later post by Joe on May 24, 2024 2 years later post by LouisDeconinck on Sep 23 Related topics Topic list, column headers with buttons are sortable. Topic Replies Views Activity How to report a SonarQube security vulnerability? SonarQube Server / Community Build 1 1.2k May 2021 How can i report security bug and a CVE(Common Vulnerabilities and Exposures) for sonarqube application, whats the procedure SonarQube Server / Community Build 1 1.4k Dec 2020 XSS Attack Prevention SonarQube Server / Community Build 5 2.3k May 2019 Vulnerability Disclosure Info SonarQube Server / Community Build 1 751 Aug 2018 Vulnerability in Confluence version SonarQube Server / Community Build documentation 2 789 Apr 2019 Sonar Solutions SAST AI solutions DevOps transformation Outsourcing software development Reduce & manage technical debt Secure by design Code coverage Code review For developers For enterprise Infrastructure as Code Public sector Products SonarQube for IDE SonarQube Server SonarQube Cloud Company About Careers Commitment to open source Customers Partners Contact us Accessibility Brand Identity Media Coverage Press releases Resources Product Demos Events Hub Customer stories White papers Learn Community Support Legal Documentation Knowledge Explore Sonar's Rules Blog Languages SonarQube Server Documentation SonarQube Cloud Documentation SonarQube for IDE Documentation Pricing Start for free Explore pricing © 2025 SonarSource Sàrl. All rights reserved.