Vulnerabilities (CVE)

Filtered by vendor Sonarsource Subscribe
Filtered by product Jenkins Plugin
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2013-5676 1 Sonarsource 2 Jenkins Plugin, Sonarqube 2023-12-10 4.0 MEDIUM N/A
The Jenkins Plugin for SonarQube 3.7 and earlier allows remote authenticated users to obtain sensitive information (cleartext passwords) by reading the value in the sonar.sonarPassword parameter from jenkins/configure.