CVE-2013-5676

Severity CVSS v4.0:
Pending analysis
Type:
CWE-310 Cryptographic Issues
Publication date:
13/12/2013
Last modified:
11/04/2025

Description

The Jenkins Plugin for SonarQube 3.7 and earlier allows remote authenticated users to obtain sensitive information (cleartext passwords) by reading the value in the sonar.sonarPassword parameter from jenkins/configure.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sonarsource:jenkins_plugin:-:-:-:*:-:sonarqube:*:*
cpe:2.3:a:sonarsource:sonarqube:*:*:*:*:*:*:*:* 3.7 (including)