CVE-2013-5676 EXPLOIT
4.0
MEDIUM · CVSS 2.0 · EPSS 5% (pctl 92)
Patch early
A public exploit exists.
Description
The Jenkins Plugin for SonarQube 3.7 and earlier allows remote authenticated users to obtain sensitive information (cleartext passwords) by reading the value in the sonar.sonarPassword parameter from jenkins/configure.
Scoring
| CVSS | 4.0 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:S/C:P/I:N/A:N |
| EPSS | 4.99% — more likely to be exploited than 92% of all CVEs |
| Weakness | CWE-310 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2013-12-13 |
| Last modified | 2026-06-16 |
Affected (2)
| Vendor | Product |
|---|---|
| sonarsource | jenkins plugin |
| sonarsource | sonarqube |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | SonarQube Jenkins Plugin - Plain Text Password | 2013-12-18 |
References
→ the Explorer · watch your stack · NVD