CVE-2020-27986

CVE-2020-27986

** DISPUTED ** SonarQube 8.4.2.36762 allows remote attackers to discover cleartext SMTP, SVN, and GitLab credentials via the api/settings/values URI. NOTE: reportedly, the vendor’s position is "it is the administrator’s responsibility to configure it."

Source: CVE-2020-27986

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다