/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-pf7c-86h6-rgpv

Published

Last updated

https://images.chainguard.dev/security/CGA-pf7c-86h6-rgpv
Package

sonarqube

RepositoryWolfi
Latest Update
Not affected
Aliases
  • CVE-2025-59250
  • GHSA-m494-w24q-6f7w

Severity

Unknown

References

  • https://nvd.nist.gov/vuln/detail/CVE-2025-59250

Updates

Status

Not affected

Justification

Vulnerable code not present

Impact

The affected component's suffix is non-standard for Maven parsing. It supports "." as a delimiter, but treats jre11 as an unknown qualifier that sorts after known ones (alpha, beta, rc, ga, etc.), which breaks version matching. This vulnerability was resolved in v25.11.0.114957 of sonarqube[1]. [1]https://github.com/SonarSource/sonarqube/commit/ad603468b3af8284156d532eae7d099464189728

Status

Under investigation


The trusted source for open source

Talk to an expert
© 2025 Chainguard. All Rights Reserved.
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing