{"id":"CVE-2018-19413","aliases":[],"url":"https://o3.security/vulnerability/CVE-2018-19413","summary":"Exposure of Sensitive Information to an Unauthorized Actor in SonarSource SonarQube API","details":"A vulnerability in the API of SonarSource SonarQube before 7.5 could allow an authenticated user to discover sensitive information such as valid user-account logins in the web application. The vulnerability occurs because of improperly configured access controls that cause the API to return the externalIdentity field to non-administrator users. The attacker could use this information in subsequent attacks against the system.","published":"2022-05-14T01:43:42Z","modified":"2024-03-04T22:46:21.813592Z","cvss":{"score":4.3,"severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.sonarsource.sonarqube:sonar-plugin-api","fixedVersion":"7.5"}],"fix":{"url":"https://github.com/SonarSource/sonarqube/commit/7b567ba3d15ed7dd0b0bba0330686487e35af85c","label":"SonarSource/sonarqube@7b567ba"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2018-19413"},{"type":"WEB","url":"https://github.com/SonarSource/sonarqube/commit/7b567ba3d15ed7dd0b0bba0330686487e35af85c"},{"type":"WEB","url":"https://jira.sonarsource.com/browse/SONAR-11305"},{"type":"WEB","url":"http://packetstormsecurity.com/files/150496/SonarSource-SonarQube-7.3-Information-Disclosure.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-03-04T22:46:21.813592Z"}}