Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6g65-wv5p-gc7r

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

In SonarQube 8.4.2.36762, an external attacker can achieve authentication bypass through SonarScanner. With an empty value for the -D sonar.login option, anonymous authentication is forced. This allows creating and overwriting public and private projects via the /api/ce/submit endpoint.

In SonarQube 8.4.2.36762, an external attacker can achieve authentication bypass through SonarScanner. With an empty value for the -D sonar.login option, anonymous authentication is forced. This allows creating and overwriting public and private projects via the /api/ce/submit endpoint.

EPSS

Процентиль: 43%
0.00208
Низкий

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 5.3
nvd
больше 5 лет назад

In SonarQube 8.4.2.36762, an external attacker can achieve authentication bypass through SonarScanner. With an empty value for the -D sonar.login option, anonymous authentication is forced. This allows creating and overwriting public and private projects via the /api/ce/submit endpoint.

EPSS

Процентиль: 43%
0.00208
Низкий

Дефекты

CWE-287