CVE-2020-27986

Severity CVSS v4.0:
Pending analysis
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
28/10/2020
Last modified:
04/08/2024

Description

SonarQube 8.4.2.36762 allows remote attackers to discover cleartext SMTP, SVN, and GitLab credentials via the api/settings/values URI. NOTE: reportedly, the vendor's position for SMTP and SVN is "it is the administrator's responsibility to configure it.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sonarsource:sonarqube:8.4.2.36762:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools