Apache Tomcat 9.0.0.M1 < 9.0.98 multiple vulnerabilities

  • which versions are you using (SonarQube Community Build - 9.9.5)
  • How is SonarQube deployed: zip
  • what are you trying to achieve: Looking for a higher version of Tomcat
  • what have you tried so far to achieve this: None

I would like to know whether the version “SonarQube Community Build - 9.9.5” is affected by the following CVEs. Please advise.

CVE-2024-50379
CVE-2024-54677
CVE-2024-56337

Tomcat:
Installed version : 9.0.85
Fixed version : 9.0.98

Hi,

I’ve unlisted your topic since you’re reporting a vulnerability. Our responsible disclosure policy asks that you email security@sonarsource.com rather than making public posts. Could you please re-send this to security@sonarsource.com?