SonarQube Public Projects Detected

info Web App Scanning Plugin ID 114468

Synopsis

SonarQube Public Projects Detected

Description

A SonarQube Public Projects response have been detected on the target web application. These response may contain sensitive information which could assist an attack to conduct further attacks.

Solution

Restrict access to the public projects endpoint or remove it.

See Also

https://next.sonarqube.com/sonarqube/web_api/api/components/suggestions?internal=true

Plugin Details

Severity: Info

ID: 114468

Type: remote

Published: 10/29/2024

Updated: 11/5/2024

Scan Template: api, basic, full, pci, scan