CVE-2020-27986

HIGH EXPLOITED NUCLEI

Sonarsource Sonarqube - Missing Authentication

Title source: rule

Description

SonarQube 8.4.2.36762 allows remote attackers to discover cleartext SMTP, SVN, and GitLab credentials via the api/settings/values URI. NOTE: reportedly, the vendor's position for SMTP and SVN is "it is the administrator's responsibility to configure it.

Nuclei Templates (1)

SonarQube - Authentication Bypass
HIGHby pikpikcu

Scores

CVSS v3 7.5
EPSS 0.9257
EPSS Percentile 99.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

VulnCheck KEV 2023-11-13
CWE
CWE-306 CWE-312
Status published
Products (1)
sonarsource/sonarqube 8.4.2.36762
Published Oct 28, 2020
Tracked Since Feb 18, 2026