Skip to content
Noroxi

SonarSource records

10 published records for vendor sonarsource.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
30%
Median publish → KEV
No record has entered KEV

All records

10 records
  • The official sonarqube docker images before alpine (Alpine specific) contain a blank password for a root user.

    CriticalCVSS 9.8No exploitEPSS 2%

    sonarsource · sonarqube docker imageDec 15, 2020

  • SonarQube 8.4.2.36762 allows remote attackers to discover cleartext SMTP, SVN, and GitLab credentials via the api/settings/values URI.

    HighCVSS 7.5Proof of conceptEPSS 16%

    sonarsource · sonarqubeOct 28, 2020

  • An insufficiently protected credentials vulnerability exists in Jenkins SonarQube Scanner Plugin 2.8 and earlier in SonarInstallation.java t

    HighCVSS 7.8No exploitEPSS 0%

    sonarsource · sonarqube scannerJan 9, 2019

  • An issue was discovered in SonarSource SonarQube before 9.9.5 LTA and 10.x before 10.5.

    HighCVSS 7.2No exploitEPSS 0%

    Oct 4, 2024

  • In SonarSource SonarQube 10.4 through 10.5 before 10.6, a vulnerability was discovered in the authorizations/group-memberships API endpoint

    HighCVSS 7.2No exploitEPSS 0%

    sonarsource · sonarqubeOct 4, 2024

  • In SonarQube before 10.4 and 9.9.4 LTA, encrypted values generated using the Settings Encryption feature are potentially exposed in cleartex

    MediumCVSS 6.5No exploitEPSS 0%

    sonarsource · sonarqubeJun 16, 2024

  • SonarSource SonarQube before 7.8 has XSS in project links on account/projects.

    MediumCVSS 6.1No exploitEPSS 1%

    sonarsource · sonarqubeOct 14, 2019

  • In SonarQube 8.4.2.36762, an external attacker can achieve authentication bypass through SonarScanner.

    MediumCVSS 5.3No exploitEPSS 1%

    sonarsource · sonarqubeNov 2, 2020

  • CVE-2013-5676
    17Monitor

    The Jenkins Plugin for SonarQube 3.7 and earlier allows remote authenticated users to obtain sensitive information (cleartext passwords) by

    MediumCVSS 4.0Proof of conceptEPSS 5%

    sonarsource · jenkins pluginDec 13, 2013

  • A vulnerability in the API of SonarSource SonarQube before 7.4 could allow an authenticated user to discover sensitive information such as v

    MediumCVSS 4.3No exploitEPSS 1%

    sonarsource · sonarqubeDec 14, 2018