SonarSource kayıtları
sonarsource üreticisine ait 10 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %30
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-306 Missing Authentication for Critical Function2
- CWE-284 Improper Access Control1
- CWE-287 Improper Authentication1
- CWE-310 Cryptographic Issues1
- CWE-522 Insufficiently Protected Credentials1
- CWE-532 Insertion of Sensitive Information into Log File1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
10 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2020-35193İstismar yok | The official sonarqube docker images before alpine (Alpine specific) contain a blank password for a root user.sonarsource · sonarqube docker image · CWE-306 | Kritik9,8 | — | %2,2 | 15 Ara 2020 |
35İzleyin | CVE-2020-27986Kavram kanıtı | SonarQube 8.4.2.36762 allows remote attackers to discover cleartext SMTP, SVN, and GitLab credentials via the api/settings/values URI.sonarsource · sonarqube · CWE-306 | Yüksek7,5 | — | %16,0 | 28 Eki 2020 |
31İzleyin | CVE-2018-1000425İstismar yok | An insufficiently protected credentials vulnerability exists in Jenkins SonarQube Scanner Plugin 2.8 and earlier in SonarInstallation.java tsonarsource · sonarqube scanner · CWE-522 | Yüksek7,8 | — | %0,3 | 9 Oca 2019 |
28İzleyin | CVE-2024-47910İstismar yok | An issue was discovered in SonarSource SonarQube before 9.9.5 LTA and 10.x before 10.5.CWE-284 | Yüksek7,2 | — | %0,5 | 4 Eki 2024 |
28İzleyin | CVE-2024-47911İstismar yok | In SonarSource SonarQube 10.4 through 10.5 before 10.6, a vulnerability was discovered in the authorizations/group-memberships API endpoint sonarsource · sonarqube · CWE-89 | Yüksek7,2 | — | %0,5 | 4 Eki 2024 |
26İzleyin | CVE-2024-38460İstismar yok | In SonarQube before 10.4 and 9.9.4 LTA, encrypted values generated using the Settings Encryption feature are potentially exposed in cleartexsonarsource · sonarqube · CWE-532 | Orta6,5 | — | %0,3 | 16 Haz 2024 |
24İzleyin | CVE-2019-17579İstismar yok | SonarSource SonarQube before 7.8 has XSS in project links on account/projects.sonarsource · sonarqube · CWE-79 | Orta6,1 | — | %0,7 | 14 Eki 2019 |
21İzleyin | CVE-2020-28002İstismar yok | In SonarQube 8.4.2.36762, an external attacker can achieve authentication bypass through SonarScanner.sonarsource · sonarqube · CWE-287 | Orta5,3 | — | %1,1 | 2 Kas 2020 |
17İzleyin | CVE-2013-5676Kavram kanıtı | The Jenkins Plugin for SonarQube 3.7 and earlier allows remote authenticated users to obtain sensitive information (cleartext passwords) by sonarsource · jenkins plugin · CWE-310 | Orta4,0 | — | %5,0 | 13 Ara 2013 |
17İzleyin | CVE-2018-19413İstismar yok | A vulnerability in the API of SonarSource SonarQube before 7.4 could allow an authenticated user to discover sensitive information such as vsonarsource · sonarqube · CWE-200 | Orta4,3 | — | %1,2 | 14 Ara 2018 |
- CVE-2020-3519340Planlayın
The official sonarqube docker images before alpine (Alpine specific) contain a blank password for a root user.
KritikCVSS 9,8İstismar yokEPSS %2sonarsource · sonarqube docker image15 Ara 2020
- CVE-2020-2798635İzleyin
SonarQube 8.4.2.36762 allows remote attackers to discover cleartext SMTP, SVN, and GitLab credentials via the api/settings/values URI.
YüksekCVSS 7,5Kavram kanıtıEPSS %16sonarsource · sonarqube28 Eki 2020
- CVE-2018-100042531İzleyin
An insufficiently protected credentials vulnerability exists in Jenkins SonarQube Scanner Plugin 2.8 and earlier in SonarInstallation.java t
YüksekCVSS 7,8İstismar yokEPSS %0sonarsource · sonarqube scanner9 Oca 2019
- CVE-2024-4791028İzleyin
An issue was discovered in SonarSource SonarQube before 9.9.5 LTA and 10.x before 10.5.
YüksekCVSS 7,2İstismar yokEPSS %04 Eki 2024
- CVE-2024-4791128İzleyin
In SonarSource SonarQube 10.4 through 10.5 before 10.6, a vulnerability was discovered in the authorizations/group-memberships API endpoint
YüksekCVSS 7,2İstismar yokEPSS %0sonarsource · sonarqube4 Eki 2024
- CVE-2024-3846026İzleyin
In SonarQube before 10.4 and 9.9.4 LTA, encrypted values generated using the Settings Encryption feature are potentially exposed in cleartex
OrtaCVSS 6,5İstismar yokEPSS %0sonarsource · sonarqube16 Haz 2024
- CVE-2019-1757924İzleyin
SonarSource SonarQube before 7.8 has XSS in project links on account/projects.
OrtaCVSS 6,1İstismar yokEPSS %1sonarsource · sonarqube14 Eki 2019
- CVE-2020-2800221İzleyin
In SonarQube 8.4.2.36762, an external attacker can achieve authentication bypass through SonarScanner.
OrtaCVSS 5,3İstismar yokEPSS %1sonarsource · sonarqube2 Kas 2020
- CVE-2013-567617İzleyin
The Jenkins Plugin for SonarQube 3.7 and earlier allows remote authenticated users to obtain sensitive information (cleartext passwords) by
OrtaCVSS 4,0Kavram kanıtıEPSS %5sonarsource · jenkins plugin13 Ara 2013
- CVE-2018-1941317İzleyin
A vulnerability in the API of SonarSource SonarQube before 7.4 could allow an authenticated user to discover sensitive information such as v
OrtaCVSS 4,3İstismar yokEPSS %1sonarsource · sonarqube14 Ara 2018