PT-2019-8736 · Jenkins · Jenkins Sonarqube Scanner Plugin
Publicado
2019-01-09
·
Atualizado
2022-05-13
·
CVE-2018-1000425
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Jenkins SonarQube Scanner Plugin versions 2.8 and earlier
Description
An insufficiently protected credentials issue exists in the SonarInstallation.java file, allowing attackers with local file system access to obtain the credentials used to connect to SonarQube.
Recommendations
For Jenkins SonarQube Scanner Plugin versions 2.8 and earlier, consider updating to a version later than 2.8 to resolve the issue.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Insufficiently Protected Credentials
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Jenkins Sonarqube Scanner Plugin