VDB
Sign up
MEDIUM

GHSA-3x9h-3p7m-33m7

Jenkins SonarQube Plugin Stores Passwords in Cleartext

Details

The Jenkins Plugin for SonarQube 3.7 and earlier allows remote authenticated users to obtain sensitive information (cleartext passwords) by reading the value in the sonar.sonarPassword parameter from jenkins/configure.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.jenkins-ci.plugins:sonar
Introduced in: 0

No fixed version published yet for org.jenkins-ci.plugins:sonar (maven). Pin to a known-safe version or switch to an alternative.

References