MEDIUM
GHSA-3x9h-3p7m-33m7
Jenkins SonarQube Plugin Stores Passwords in Cleartext
Details
The Jenkins Plugin for SonarQube 3.7 and earlier allows remote authenticated users to obtain sensitive information (cleartext passwords) by reading the value in the sonar.sonarPassword parameter from jenkins/configure.
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven/org.jenkins-ci.plugins:sonar
Introduced in:
0No fixed version published yet for org.jenkins-ci.plugins:sonar (maven). Pin to a known-safe version or switch to an alternative.