SonarQube
cpe:2.3:a:sonarsource:sonarqube:*:*:*:*:*:*:*
- 8.4.2.36762
A vulnerability in SonarQube version 8.4.2.36762 allows remote attackers to access cleartext credentials for SMTP, SVN, and GitLab through the api/settings/values endpoint. This issue arises because these credentials are stored in plaintext and can be retrieved without authentication, exposing sensitive information from integrations with other tools in the agile process.
Exploitation of this vulnerability leads to unauthorized access to cleartext credentials for GitLab, SVN, and SMTP, which could be used to compromise accounts or services associated with these integrations.
The vulnerability can be reproduced by sending a request to the SonarQube server's api/settings/values endpoint. This can be done without authentication, and the response will include the exposed cleartext credentials for GitLab, SVN, and SMTP.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.