QID 997278

Date Published: 2024-02-20

QID 997278: Java (Maven) Security Update for org.jenkins-ci.plugins:sonar (GHSA-3ccq-gccx-pm7j)

An insufficiently protected credentials vulnerability exists in Jenkins SonarQube Scanner Plugin 2.8 and earlier in SonarInstallation.java that allows attackers with local file system access to obtain the credentials used to connect to SonarQube.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as Low - 2.1 severity.
  • Solution
    Refer to Github security advisory GHSA-3ccq-gccx-pm7j for updates and patch information.
    Vendor References

    CVEs related to QID 997278

    Software Advisories
    Advisory ID Software Component Link
    GHSA-3ccq-gccx-pm7j org.jenkins-ci.plugins:sonar URL Logo github.com/advisories/GHSA-3ccq-gccx-pm7j