CVE-2025-62292

In SonarQube before 25.6, 2025.3 Commercial, and 2025.1.3 LTA, authenticated low-privileged users can query the /api/v2/users-management/users endpoint and obtain user fields intended for administrators only, including the email addresses of other accounts.
Configurations

No configuration.

History

10 Oct 2025, 07:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-10 07:15

Updated : 2025-10-14 19:37


NVD link : CVE-2025-62292

Mitre link : CVE-2025-62292

CVE.ORG link : CVE-2025-62292


JSON object : View

Products Affected

No product.

CWE
CWE-669

Incorrect Resource Transfer Between Spheres