Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m643-2pfv-xwm8

Опубликовано: 14 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 4.3

Описание

Exposure of Sensitive Information to an Unauthorized Actor in SonarSource SonarQube API

A vulnerability in the API of SonarSource SonarQube before 7.5 could allow an authenticated user to discover sensitive information such as valid user-account logins in the web application. The vulnerability occurs because of improperly configured access controls that cause the API to return the externalIdentity field to non-administrator users. The attacker could use this information in subsequent attacks against the system.

Пакеты

Наименование

org.sonarsource.sonarqube:sonar-plugin-api

maven
Затронутые версииВерсия исправления

< 7.5

7.5

EPSS

Процентиль: 67%
0.00541
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 4.3
nvd
около 7 лет назад

A vulnerability in the API of SonarSource SonarQube before 7.4 could allow an authenticated user to discover sensitive information such as valid user-account logins in the web application. The vulnerability occurs because of improperly configured access controls that cause the API to return the externalIdentity field to non-administrator users. The attacker could use this information in subsequent attacks against the system.

EPSS

Процентиль: 67%
0.00541
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-200