Записи SonarSource
10 опубликованных записей вендора sonarsource.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 30 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-306 Missing Authentication for Critical Function2
- CWE-284 Improper Access Control1
- CWE-287 Improper Authentication1
- CWE-310 Cryptographic Issues1
- CWE-522 Insufficiently Protected Credentials1
- CWE-532 Insertion of Sensitive Information into Log File1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
10 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2020-35193Эксплойта нет | The official sonarqube docker images before alpine (Alpine specific) contain a blank password for a root user.sonarsource · sonarqube docker image · CWE-306 | Критическая9,8 | — | 2,2 % | 15 дек. 2020 г. |
35Наблюдать | CVE-2020-27986Proof of concept | SonarQube 8.4.2.36762 allows remote attackers to discover cleartext SMTP, SVN, and GitLab credentials via the api/settings/values URI.sonarsource · sonarqube · CWE-306 | Высокая7,5 | — | 16,0 % | 28 окт. 2020 г. |
31Наблюдать | CVE-2018-1000425Эксплойта нет | An insufficiently protected credentials vulnerability exists in Jenkins SonarQube Scanner Plugin 2.8 and earlier in SonarInstallation.java tsonarsource · sonarqube scanner · CWE-522 | Высокая7,8 | — | 0,3 % | 9 янв. 2019 г. |
28Наблюдать | CVE-2024-47910Эксплойта нет | An issue was discovered in SonarSource SonarQube before 9.9.5 LTA and 10.x before 10.5.CWE-284 | Высокая7,2 | — | 0,5 % | 4 окт. 2024 г. |
28Наблюдать | CVE-2024-47911Эксплойта нет | In SonarSource SonarQube 10.4 through 10.5 before 10.6, a vulnerability was discovered in the authorizations/group-memberships API endpoint sonarsource · sonarqube · CWE-89 | Высокая7,2 | — | 0,5 % | 4 окт. 2024 г. |
26Наблюдать | CVE-2024-38460Эксплойта нет | In SonarQube before 10.4 and 9.9.4 LTA, encrypted values generated using the Settings Encryption feature are potentially exposed in cleartexsonarsource · sonarqube · CWE-532 | Средняя6,5 | — | 0,3 % | 16 июн. 2024 г. |
24Наблюдать | CVE-2019-17579Эксплойта нет | SonarSource SonarQube before 7.8 has XSS in project links on account/projects.sonarsource · sonarqube · CWE-79 | Средняя6,1 | — | 0,7 % | 14 окт. 2019 г. |
21Наблюдать | CVE-2020-28002Эксплойта нет | In SonarQube 8.4.2.36762, an external attacker can achieve authentication bypass through SonarScanner.sonarsource · sonarqube · CWE-287 | Средняя5,3 | — | 1,1 % | 2 нояб. 2020 г. |
17Наблюдать | CVE-2013-5676Proof of concept | The Jenkins Plugin for SonarQube 3.7 and earlier allows remote authenticated users to obtain sensitive information (cleartext passwords) by sonarsource · jenkins plugin · CWE-310 | Средняя4,0 | — | 5,0 % | 13 дек. 2013 г. |
17Наблюдать | CVE-2018-19413Эксплойта нет | A vulnerability in the API of SonarSource SonarQube before 7.4 could allow an authenticated user to discover sensitive information such as vsonarsource · sonarqube · CWE-200 | Средняя4,3 | — | 1,2 % | 14 дек. 2018 г. |
- CVE-2020-3519340В плане
The official sonarqube docker images before alpine (Alpine specific) contain a blank password for a root user.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %sonarsource · sonarqube docker image15 дек. 2020 г.
- CVE-2020-2798635Наблюдать
SonarQube 8.4.2.36762 allows remote attackers to discover cleartext SMTP, SVN, and GitLab credentials via the api/settings/values URI.
ВысокаяCVSS 7,5Proof of conceptEPSS 16 %sonarsource · sonarqube28 окт. 2020 г.
- CVE-2018-100042531Наблюдать
An insufficiently protected credentials vulnerability exists in Jenkins SonarQube Scanner Plugin 2.8 and earlier in SonarInstallation.java t
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %sonarsource · sonarqube scanner9 янв. 2019 г.
- CVE-2024-4791028Наблюдать
An issue was discovered in SonarSource SonarQube before 9.9.5 LTA and 10.x before 10.5.
ВысокаяCVSS 7,2Эксплойта нетEPSS 0 %4 окт. 2024 г.
- CVE-2024-4791128Наблюдать
In SonarSource SonarQube 10.4 through 10.5 before 10.6, a vulnerability was discovered in the authorizations/group-memberships API endpoint
ВысокаяCVSS 7,2Эксплойта нетEPSS 0 %sonarsource · sonarqube4 окт. 2024 г.
- CVE-2024-3846026Наблюдать
In SonarQube before 10.4 and 9.9.4 LTA, encrypted values generated using the Settings Encryption feature are potentially exposed in cleartex
СредняяCVSS 6,5Эксплойта нетEPSS 0 %sonarsource · sonarqube16 июн. 2024 г.
- CVE-2019-1757924Наблюдать
SonarSource SonarQube before 7.8 has XSS in project links on account/projects.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %sonarsource · sonarqube14 окт. 2019 г.
- CVE-2020-2800221Наблюдать
In SonarQube 8.4.2.36762, an external attacker can achieve authentication bypass through SonarScanner.
СредняяCVSS 5,3Эксплойта нетEPSS 1 %sonarsource · sonarqube2 нояб. 2020 г.
- CVE-2013-567617Наблюдать
The Jenkins Plugin for SonarQube 3.7 and earlier allows remote authenticated users to obtain sensitive information (cleartext passwords) by
СредняяCVSS 4,0Proof of conceptEPSS 5 %sonarsource · jenkins plugin13 дек. 2013 г.
- CVE-2018-1941317Наблюдать
A vulnerability in the API of SonarSource SonarQube before 7.4 could allow an authenticated user to discover sensitive information such as v
СредняяCVSS 4,3Эксплойта нетEPSS 1 %sonarsource · sonarqube14 дек. 2018 г.