CVSS—
共找到 6 条公开漏洞记录
SonarQube contains a default login vulnerability. An attacker can obtain access to user accounts and access sensitive information, modify data, and/or execute unauthorized operations.
Information leakage vulnerability in an interface of SonarQube, you can download the source code through the tool.
SonarQube 8.4.2.36762 allows remote attackers to discover cleartext SMTP, SVN, and GitLab credentials via the api/settings/values URI.