SonarSource records
10 published records for vendor sonarsource.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 30%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-306 Missing Authentication for Critical Function2
- CWE-284 Improper Access Control1
- CWE-287 Improper Authentication1
- CWE-310 Cryptographic Issues1
- CWE-522 Insufficiently Protected Credentials1
- CWE-532 Insertion of Sensitive Information into Log File1
The weakness classes this vendor ships most often: where to look.
CWEAll records
10 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2020-35193No exploit | The official sonarqube docker images before alpine (Alpine specific) contain a blank password for a root user.sonarsource · sonarqube docker image · CWE-306 | Critical9.8 | — | 2.2% | Dec 15, 2020 |
35Monitor | CVE-2020-27986Proof of concept | SonarQube 8.4.2.36762 allows remote attackers to discover cleartext SMTP, SVN, and GitLab credentials via the api/settings/values URI.sonarsource · sonarqube · CWE-306 | High7.5 | — | 16.0% | Oct 28, 2020 |
31Monitor | CVE-2018-1000425No exploit | An insufficiently protected credentials vulnerability exists in Jenkins SonarQube Scanner Plugin 2.8 and earlier in SonarInstallation.java tsonarsource · sonarqube scanner · CWE-522 | High7.8 | — | 0.3% | Jan 9, 2019 |
28Monitor | CVE-2024-47910No exploit | An issue was discovered in SonarSource SonarQube before 9.9.5 LTA and 10.x before 10.5.CWE-284 | High7.2 | — | 0.5% | Oct 4, 2024 |
28Monitor | CVE-2024-47911No exploit | In SonarSource SonarQube 10.4 through 10.5 before 10.6, a vulnerability was discovered in the authorizations/group-memberships API endpoint sonarsource · sonarqube · CWE-89 | High7.2 | — | 0.5% | Oct 4, 2024 |
26Monitor | CVE-2024-38460No exploit | In SonarQube before 10.4 and 9.9.4 LTA, encrypted values generated using the Settings Encryption feature are potentially exposed in cleartexsonarsource · sonarqube · CWE-532 | Medium6.5 | — | 0.3% | Jun 16, 2024 |
24Monitor | CVE-2019-17579No exploit | SonarSource SonarQube before 7.8 has XSS in project links on account/projects.sonarsource · sonarqube · CWE-79 | Medium6.1 | — | 0.7% | Oct 14, 2019 |
21Monitor | CVE-2020-28002No exploit | In SonarQube 8.4.2.36762, an external attacker can achieve authentication bypass through SonarScanner.sonarsource · sonarqube · CWE-287 | Medium5.3 | — | 1.1% | Nov 2, 2020 |
17Monitor | CVE-2013-5676Proof of concept | The Jenkins Plugin for SonarQube 3.7 and earlier allows remote authenticated users to obtain sensitive information (cleartext passwords) by sonarsource · jenkins plugin · CWE-310 | Medium4.0 | — | 5.0% | Dec 13, 2013 |
17Monitor | CVE-2018-19413No exploit | A vulnerability in the API of SonarSource SonarQube before 7.4 could allow an authenticated user to discover sensitive information such as vsonarsource · sonarqube · CWE-200 | Medium4.3 | — | 1.2% | Dec 14, 2018 |
- CVE-2020-3519340Plan
The official sonarqube docker images before alpine (Alpine specific) contain a blank password for a root user.
CriticalCVSS 9.8No exploitEPSS 2%sonarsource · sonarqube docker imageDec 15, 2020
- CVE-2020-2798635Monitor
SonarQube 8.4.2.36762 allows remote attackers to discover cleartext SMTP, SVN, and GitLab credentials via the api/settings/values URI.
HighCVSS 7.5Proof of conceptEPSS 16%sonarsource · sonarqubeOct 28, 2020
- CVE-2018-100042531Monitor
An insufficiently protected credentials vulnerability exists in Jenkins SonarQube Scanner Plugin 2.8 and earlier in SonarInstallation.java t
HighCVSS 7.8No exploitEPSS 0%sonarsource · sonarqube scannerJan 9, 2019
- CVE-2024-4791028Monitor
An issue was discovered in SonarSource SonarQube before 9.9.5 LTA and 10.x before 10.5.
HighCVSS 7.2No exploitEPSS 0%Oct 4, 2024
- CVE-2024-4791128Monitor
In SonarSource SonarQube 10.4 through 10.5 before 10.6, a vulnerability was discovered in the authorizations/group-memberships API endpoint
HighCVSS 7.2No exploitEPSS 0%sonarsource · sonarqubeOct 4, 2024
- CVE-2024-3846026Monitor
In SonarQube before 10.4 and 9.9.4 LTA, encrypted values generated using the Settings Encryption feature are potentially exposed in cleartex
MediumCVSS 6.5No exploitEPSS 0%sonarsource · sonarqubeJun 16, 2024
- CVE-2019-1757924Monitor
SonarSource SonarQube before 7.8 has XSS in project links on account/projects.
MediumCVSS 6.1No exploitEPSS 1%sonarsource · sonarqubeOct 14, 2019
- CVE-2020-2800221Monitor
In SonarQube 8.4.2.36762, an external attacker can achieve authentication bypass through SonarScanner.
MediumCVSS 5.3No exploitEPSS 1%sonarsource · sonarqubeNov 2, 2020
- CVE-2013-567617Monitor
The Jenkins Plugin for SonarQube 3.7 and earlier allows remote authenticated users to obtain sensitive information (cleartext passwords) by
MediumCVSS 4.0Proof of conceptEPSS 5%sonarsource · jenkins pluginDec 13, 2013
- CVE-2018-1941317Monitor
A vulnerability in the API of SonarSource SonarQube before 7.4 could allow an authenticated user to discover sensitive information such as v
MediumCVSS 4.3No exploitEPSS 1%sonarsource · sonarqubeDec 14, 2018