QID 12458
Date Published: 2021-05-20
QID 12458: SonarQube Accessible via Default Credentials
SonarQube is an automatic code review tool to detect bugs, vulnerabilities, and code smells in your code. It can integrate with your existing workflow to enable continuous code inspection across your project branches and pull requests.
QID Detection Logic:(Unauthenticated)
This QID sends HTTP POST request to "api/authentication/login" to log in with (admin:admin) to see if the login was successful or not.
Successful exploitation of this vulnerability can impact the Integrity, Availability, and Confidentiality of the target system.
Solution
Customers are advised not to use default credentials for SonarQube.
Vendor References
CVEs related to QID 12458
Software Advisories
| Advisory ID | Software | Component | Link |
|---|