Record summary

CVE-2020-27986 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

SonarQube 8.4.2.36762 allows remote attackers to discover cleartext SMTP, SVN, and GitLab credentials via the api/settings/values URI. NOTE: reportedly, the vendor's position for SMTP and SVN is "it is the administrator's responsibility to configure it.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Nov 13, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated May 1, 2024 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: unknown

CVE List, VulnCheck8.4.2.36762affected

Nuclei templates

1
ProjectDiscoveryHIGHSonarQube - Authentication BypassCVSS 7.5

SonarQube 8.4.2.36762 allows remote attackers to discover cleartext SMTP, SVN, and GitLab credentials via the api/settings/values URI.

Impact

Successful exploitation of this vulnerability could allow an attacker to bypass authentication and gain unauthorized access to sensitive information.

Remediation

Reportedly, the vendor's position for SMTP and SVN is "it is the administrator's responsibility to configure it."

WeaknessesCWE-306
Authorspikpikcu
Template tagscvecve2020sonarqubesonarsourcevkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:sonarsource:sonarqube:8.4.2.36762:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

2