CVE-2020-27986
sonarsource sonarqube Missing Authentication for Critical Function
Record summary
CVE-2020-27986 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
SonarQube 8.4.2.36762 allows remote attackers to discover cleartext SMTP, SVN, and GitLab credentials via the api/settings/values URI. NOTE: reportedly, the vendor's position for SMTP and SVN is "it is the administrator's responsibility to configure it.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Nov 13, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated May 1, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
sonarqubeBrowse sonarsource / sonarqubeDefault status: unknown | CVE List, VulnCheck | 8.4.2.36762 | affected |
Nuclei templates
1ProjectDiscoveryHIGHSonarQube - Authentication BypassCVSS 7.5
SonarQube 8.4.2.36762 allows remote attackers to discover cleartext SMTP, SVN, and GitLab credentials via the api/settings/values URI.
Impact
Successful exploitation of this vulnerability could allow an attacker to bypass authentication and gain unauthorized access to sensitive information.
Remediation
Reportedly, the vendor's position for SMTP and SVN is "it is the administrator's responsibility to configure it."
Source: ProjectDiscovery