Vulnerabilities > Sonarsource > Sonarqube > 8.4.2.36762

DATE CVE VULNERABILITY TITLE RISK
2020-11-02 CVE-2020-28002 Improper Authentication vulnerability in Sonarsource Sonarqube 8.4.2.36762
In SonarQube 8.4.2.36762, an external attacker can achieve authentication bypass through SonarScanner.
network
low complexity
sonarsource CWE-287
5.0
2020-10-28 CVE-2020-27986 Cleartext Storage of Sensitive Information vulnerability in Sonarsource Sonarqube 8.4.2.36762
SonarQube 8.4.2.36762 allows remote attackers to discover cleartext SMTP, SVN, and GitLab credentials via the api/settings/values URI.
network
low complexity
sonarsource CWE-312
7.5