4
CVSSv2

CVE-2013-5676

Published: 13/12/2013 Updated: 16/12/2013
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
VMScore: 405
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

The Jenkins Plugin for SonarQube 3.7 and previous versions allows remote authenticated users to obtain sensitive information (cleartext passwords) by reading the value in the sonar.sonarPassword parameter from jenkins/configure.

Vulnerable Product Search on Vulmon Subscribe to Product

sonarsource jenkins_plugin -

Vendor Advisories

The Jenkins Plugin for SonarQube 37 and earlier allows remote authenticated users to obtain sensitive information (cleartext passwords) by reading the value in the sonarsonarPassword parameter from jenkins/configure ...

Exploits

################################################### 1 ### Advisory Information ### Title: SonarQube Jenkins Plugin - Plain Text Password Date published: 2013-12-05 Date of last update: 2013-12-05 Vendors contacted: SonarQube and Jenkins CI Discovered by: Christian Catalano Severity: High 2 ### Vulnerability Information ### CVE reference ...
The SonarQube Jenkins plugin in Jenkins CI suffers from a plain text password disclosure vulnerability ...