We are using Sonarqube EE 8.9 LTS and we have got the following vulnerabilities. May I know is this really vulnerable for non-public faced Sonarqube instance? if yes how to fix this?
CVEs: CVE-2022-22970, CVE-2022-22971
Title: Spring Framework Denial of Service (DoS) Vulnerability
Dear Mohan Manokaran,
Thank you for bringing these vulnerabilities to our attention. We take security very seriously and appreciate your efforts in helping us to maintain a secure product.
On this occasion, the reported findings affect SonarQube EE 8.9 LTS.
As per our patch policy, we support only 2 versions of SonarQube: the LTS and the latest .
As soon as a more recent version of SonarQube exists, we stop patching old non-LTS versions of SonarQube. We therefore highly recommend that you update to the latest SonarQube 9.9 LTS Enterprise Edition to ensure that your environment is protected against any known vulnerabilities.
Please do continue to report any vulnerabilities you find in future using our process.
How to report a vulnerability responsibly:
Follow this guide if you’ve found a vulnerability in one of SonarSource’s products or websites and you want to responsibly report it.
SonarSource customers with a support contract can report the vulnerability directly through the support channel.
Otherwise, send an email to email@example.com.
What we need from you:
Detail the steps you followed that make the vulnerability exploitable including any URLs or code you used. The more information you provide, the faster we can reproduce and fix the problem.
Please don’t send PDF, DOC, or EXE files or reports generated by DAST products. We will not look at them. We do accept images.
- Cross-site scripting (XSS)
- SQL injection (SQLi)
- Cross-site request forgery (CSRF)
- Remote code execution (RCE)
- Cookies not used for authentication or CSRF protection, not being marked as Secure or HTTPOnly
- Data breaches, such as data of private projects or private organizations on SonarCloud.
You need to get our permission before disclosing an issue publicly. We’ll only consider your public disclosure request after we’ve fixed the reported vulnerability.