peter bassill · operator
$ cve CVE-2013-5676 JSON

CVE-2013-5676 EXPLOIT

4.0
MEDIUM · CVSS 2.0 · EPSS 5% (pctl 92)

Patch early

A public exploit exists.

Description

The Jenkins Plugin for SonarQube 3.7 and earlier allows remote authenticated users to obtain sensitive information (cleartext passwords) by reading the value in the sonar.sonarPassword parameter from jenkins/configure.

Scoring

CVSS4.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:S/C:P/I:N/A:N
EPSS4.99% — more likely to be exploited than 92% of all CVEs
WeaknessCWE-310
On CISA KEVno
Public exploityes
Published2013-12-13
Last modified2026-06-16

Affected (2)

VendorProduct
sonarsourcejenkins plugin
sonarsourcesonarqube

Public exploits

SourceTitleDate
exploit-dbSonarQube Jenkins Plugin - Plain Text Password2013-12-18

References

→ the Explorer  ·  watch your stack  ·  NVD