Vulnerability Description
SonarQube 8.4.2.36762 allows remote attackers to discover cleartext SMTP, SVN, and GitLab credentials via the api/settings/values URI. NOTE: reportedly, the vendor's position for SMTP and SVN is "it is the administrator's responsibility to configure it.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sonarsource | Sonarqube | 8.4.2.36762 |
Related Weaknesses (CWE)
References
- https://csl.com.co/sonarqube-auditando-al-auditor-parte-i/Vendor Advisory
- https://csl.com.co/sonarqube-auditando-al-auditor-parte-i/Vendor Advisory
FAQ
What is CVE-2020-27986?
CVE-2020-27986 is a vulnerability with a CVSS score of 7.5 (HIGH). SonarQube 8.4.2.36762 allows remote attackers to discover cleartext SMTP, SVN, and GitLab credentials via the api/settings/values URI. NOTE: reportedly, the vendor's position for SMTP and SVN is "it i...
How severe is CVE-2020-27986?
CVE-2020-27986 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-27986?
Check the references section above for vendor advisories and patch information. Affected products include: Sonarsource Sonarqube.