S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2020-27986 Scanner

CVE-2020-27986 scanner - Information Disclosure vulnerability in SonarQube

Est. Time~30 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.3k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2020-27986
7.5
CVSShigh
Exploitable remotely over the internet · no authentication required.

SonarQube 8.4.2.36762 allows remote attackers to discover cleartext SMTP, SVN, and GitLab credentials via the api/settings/values URI. NOTE: reportedly, the vendor's position for SMTP and SVN is "it is the administrator's responsibility to configure it.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
sonarqubeby sonarsource
8.4.2.36762
Updated Aug 21, 2026View on NVD →
Detail

SonarQube is an open-source tool used for continuous code inspection and analysis to identify and address code quality and security vulnerabilities. It is widely used in software development projects to improve the quality, reliability, and maintainability of the codebase. The tool scans the codebase for a wide range of security issues, such as buffer overflows and cross-site scripting (XSS) attacks, generating reports and metrics that can be used to prioritize remediation efforts.

CVE-2020-27986 is a security vulnerability detected in SonarQube version 8.4.2.36762 that allows remote attackers to discover cleartext SMTP, SVN, and GitLab credentials through the api/settings/values URI. Attackers can exploit this vulnerability to gain unauthorized access to the target system by using the stolen credentials.

Exploitation of this vulnerability can lead to a severe risk of data breach and leakage. Attackers can misuse the stolen credentials to gain unauthorized access to sensitive information, inject malicious code into the codebase, or cause the system to crash, leading to significant data loss and business disruption.

s4e.io, a platform that offers pro features for vulnerability detection and risk assessment, can help users identify vulnerabilities in their digital assets quickly and easily. By leveraging its advanced scanning and analysis capabilities, users can gain comprehensive insights into the security posture of their systems, applications, and infrastructure, and take concrete steps to mitigate any identified risks. With s4e.io, users can rest assured that their digital assets are secure and protected against the latest threats and vulnerabilities.

 

REFERENCES

Solution Advice

Upgrade to the latest version of SonarQube to mitigate the vulnerability.

  • Review access controls and permissions to ensure that only authorized personnel have access to sensitive system resources.
  • Implement two-factor authentication to add an additional layer of security to the authentication process.
  • Deploy a firewall or intrusion detection system to monitor and block unauthorized access attempts to the system.
  • Remind developers to avoid including sensitive information, such as plain-text passwords, in code comments or scripts.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.