Skip to content

CVE with CVSS Score of 9.8 is reported as Major on SonarQube #1053

@mnisius

Description

@mnisius

Describe the bug
In my Project the CVE-2025-31651 with a CVSS Score of 9.8 was discovered. In SonarQube this Issue is now shown as a Major instead of a Critical or Blocker.

To Reproduce
Scan a Spring Boot Project with Spring Boot 3.4.2. Create a Owasp Report with dependency-check-maven, and perform a sonarqube analysis with the maven:sonar-maven-plugin.

Current behavior
The issue is marked as Major

Expected behavior
The issue should be in the Category Blocker or Critcal

  • dependency-check: 12.1.0
  • sonarqube: Enterprise Edition v2025.1 (102418)
  • dependency-check-sonar-plugin5.0.0

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions