Maven package
org.sonarsource.sonarqube/sonar-plugin-api
pkg:maven/org.sonarsource.sonarqube/sonar-plugin-api
Vulnerabilities (1)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2018-19413 | Med | 4.3 | < 7.5 | 7.5 | Dec 14, 2018 | A vulnerability in the API of SonarSource SonarQube before 7.4 could allow an authenticated user to discover sensitive information such as valid user-account logins in the web application. The vulnerability occurs because of improperly configured access controls that cause the AP |
- affected < 7.5fixed 7.5
A vulnerability in the API of SonarSource SonarQube before 7.4 could allow an authenticated user to discover sensitive information such as valid user-account logins in the web application. The vulnerability occurs because of improperly configured access controls that cause the AP