CVE-2013-5676

The Jenkins Plugin for SonarQube 3.7 and earlier allows remote authenticated users to obtain sensitive information (cleartext passwords) by reading the value in the sonar.sonarPassword parameter from jenkins/configure.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:sonarsource:jenkins_plugin:-:-:-:*:-:sonarqube:*:*
cpe:2.3:a:sonarsource:sonarqube:*:*:*:*:*:*:*:*

Information

Published : 2013-12-13 10:55

Updated : 2013-12-16 09:16


NVD link : CVE-2013-5676

Mitre link : CVE-2013-5676


JSON object : View

CWE
CWE-310

Cryptographic Issues

Advertisement

dedicated server usa

Products Affected

sonarsource

  • jenkins_plugin
  • sonarqube