Lucene search

K

Sonarqube Security Vulnerabilities

cve
cve

CVE-2018-19413

A vulnerability in the API of SonarSource SonarQube before 7.4 could allow an authenticated user to discover sensitive information such as valid user-account logins in the web application. The vulnerability occurs because of improperly configured access controls that cause the API to return the ext...

4.3CVSS

4.3AI Score

0.001EPSS

2018-12-14 03:29 PM
45
cve
cve

CVE-2019-17579

SonarSource SonarQube before 7.8 has XSS in project links on account/projects.

6.1CVSS

5.9AI Score

0.001EPSS

2019-10-14 03:15 PM
51
cve
cve

CVE-2020-27986

SonarQube 8.4.2.36762 allows remote attackers to discover cleartext SMTP, SVN, and GitLab credentials via the api/settings/values URI. NOTE: reportedly, the vendor's position for SMTP and SVN is "it is the administrator's responsibility to configure it.

7.5CVSS

7.4AI Score

0.369EPSS

2020-10-28 11:15 PM
50
cve
cve

CVE-2020-28002

In SonarQube 8.4.2.36762, an external attacker can achieve authentication bypass through SonarScanner. With an empty value for the -D sonar.login option, anonymous authentication is forced. This allows creating and overwriting public and private projects via the /api/ce/submit endpoint.

5.3CVSS

5.5AI Score

0.001EPSS

2020-11-02 09:15 PM
17