Vulnerabilities (CVE)

Filtered by vendor Sonarsource Subscribe
Filtered by product Sonarqube
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-27986 1 Sonarsource 1 Sonarqube 2021-07-21 5.0 MEDIUM 7.5 HIGH
** DISPUTED ** SonarQube 8.4.2.36762 allows remote attackers to discover cleartext SMTP, SVN, and GitLab credentials via the api/settings/values URI. NOTE: reportedly, the vendor's position for SMTP and SVN is "it is the administrator's responsibility to configure it."