QID 730412

Date Published: 2022-03-29

QID 730412: SonarSource SonarQube Authentication Bypass Vulnerability (CVE-2020-28002)

In SonarQube 8.4.2.36762, an external attacker can achieve an authentication bypass through SonarScanner.

QID Detection Logic:(Unauthenticated)
QID checks for the version in the response of http request "/api/system/status".

QID Detection Logic:(authenticated)
QID checks for the version in the ps command output.

With an empty value for the -D sonar.login option, anonymous authentication is forced. This allows creating and overwriting public and private projects via the /api/ce/submit endpoint.

  • CVSS V3 rated as Medium - 5.3 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Users are advised to upgrade to SonarQube latest version.
    Vendor References

    CVEs related to QID 730412

    Software Advisories
    Advisory ID Software Component Link
    CVE-2020-28002 URL Logo www.sonarqube.org/downloads/