Hello Sandy7894,Maarten,
Thank you for reaching out to us; we take all customer vulnerability reports very seriously.
None of these SonarQube versions are vulnerable to CVE-2022-42889. However, SQ 9.3 and 9.5 are no longer supported; hence our advice is to update to the last release, 9.7, which of course, is not vulnerable either.
Please let me know if you have any further questions.
Kind regards,
Emanuele