An insufficiently protected credentials vulnerability exists in Jenkins SonarQube Scanner Plugin 2.8 and earlier in SonarInstallation.java that allows attackers with local file system access to obtain the credentials used to connect to SonarQube.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2019-01-09T23:00:00

Updated: 2024-08-05T12:40:46.979Z

Reserved: 2019-01-09T00:00:00

Link: CVE-2018-1000425

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2019-01-09T23:29:02.967

Modified: 2020-08-24T17:37:01.140

Link: CVE-2018-1000425

cve-icon Redhat

No data.