QID 730412
Date Published: 2022-03-29
QID 730412: SonarSource SonarQube Authentication Bypass Vulnerability (CVE-2020-28002)
In SonarQube 8.4.2.36762, an external attacker can achieve an authentication bypass through SonarScanner.
QID Detection Logic:(Unauthenticated)
QID checks for the version in the response of http request "/api/system/status".
QID Detection Logic:(authenticated)
QID checks for the version in the ps command output.
With an empty value for the -D sonar.login option, anonymous authentication is forced. This allows creating and overwriting public and private projects via the /api/ce/submit endpoint.
Solution
Users are advised to upgrade to SonarQube latest version.
Vendor References
- CVE-2020-28002 -
csl.com.co/sonarqube-auditando-al-auditor-parte-ii/
CVEs related to QID 730412
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2020-28002 |
|