- Version: Sonarqube 9.9.3 Enterprise edition
- How is SonarQube deployed: zip
We are installing this version in our on-prem server. Before going production our Cibersecurity area ran som security tests on the SonarQube URL. Unfortunately they found a high vulnerability: The “path traversal” one that it is supposed to be fixed as soon as possible.
References:
- CWE - CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (4.15)
- Path Traversal | OWASP Foundation
I wonder if this is something you are aware of or if it is fixed in any other version. I tried to look for it in your jira but found nothing.
Thanks