Description
SonarQube 8.4.2.36762 allows remote attackers to discover cleartext SMTP, SVN, and GitLab credentials via the api/settings/values URI. NOTE: reportedly, the vendor's position for SMTP and SVN is "it is the administrator's responsibility to configure it.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
| Link | Providers |
|---|---|
| https://csl.com.co/sonarqube-auditando-al-auditor-parte-i/ |
|
History
Mon, 23 Feb 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T16:25:43.905Z
Reserved: 2020-10-28T00:00:00.000Z
Link: CVE-2020-27986
Updated: 2024-08-04T16:25:43.905Z
Status : Modified
Published: 2020-10-28T23:15:12.410
Modified: 2024-11-21T05:22:09.017
Link: CVE-2020-27986
No data.
OpenCVE Enrichment
No data.