Skip to main content
0-Doubt
NewsInvestorsQuestionnairesDeveloperHelp
AnonymousSign in
0-Doubt — neutral IT/Security research
BrowseResellersCertified analystsRFI/RFP questionnairesHow trust worksHelp & FAQAPI
  1. Home/
  2. Sonar/
  3. SonarSource SonarQube

SonarSource SonarQube

AI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Secure coding rating: 0/100How this score is computedA product with no known CVEs starts at a neutral score and climbs the longer it goes without one; a product with known CVEs is penalized by severity instead. This one has 9 known CVEs (vendor-level match — see the CVE list below) and is tracked as ~39 days old in our catalog (a stand-in for real release date, which we don't track). The platform admin controls the formula's weights.

Code quality and security platform with SAST, SCA, and AI-powered remediation

by Sonar · sonarsource.com · source ↗

Known CVEs (9)About this listSourced from the public NVD database, matched by vendor name. Shown here at the vendor level — we don't track per-product/version data, so a listed CVE may affect a different product from this vendor, not necessarily this one. “New” means published within the last 30 days. “Actively exploited” means CISA's Known Exploited Vulnerabilities (KEV) catalog confirms real-world exploitation, not just a theoretical severity score.

RSS ⇢
  • CVE-2024-47161 ↗MEDIUM 4.32024

    In JetBrains TeamCity before 2024.07.3 password could be exposed via Sonar runner REST API

  • CVE-2023-24442 ↗MEDIUM 5.52023

    Jenkins GitHub Pull Request Coverage Status Plugin 2.2.0 and earlier stores the GitHub Personal Access Token, Sonar access token and Sonar password unencrypted in its global configuration file on the …

  • CVE-2022-46688 ↗MEDIUM 6.52022

    A cross-site request forgery (CSRF) vulnerability in Jenkins Sonar Gerrit Plugin 377.v8f3808963dc5 and earlier allows attackers to have Jenkins connect to Gerrit servers (previously configured by Jenk…

  • CVE-2020-28443 ↗CRITICAL 9.82022

    This affects all versions of package sonar-wrapper. The injection point is located in lib/sonarRunner.js.

  • CVE-2020-28002 ↗MEDIUM 5.32020

    In SonarQube 8.4.2.36762, an external attacker can achieve authentication bypass through SonarScanner. With an empty value for the -D sonar.login option, anonymous authentication is forced. This allow…

  • CVE-2020-2150 ↗MEDIUM 5.32020

    Jenkins Sonar Quality Gates Plugin 1.3.1 and earlier transmits configured credentials in plain text as part of its global Jenkins configuration form, potentially resulting in their exposure.

  • CVE-2019-12752 ↗MEDIUM 6.12019

    The Symantec SONAR component, prior to 12.0.2, may be susceptible to a tamper protection bypass vulnerability which could potentially allow an attacker to circumvent the existing tamper protection in …

  • CVE-2019-10467 ↗MEDIUM 6.52019

    Jenkins Sonar Gerrit Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file s…

  • CVE-2013-5676 ↗MEDIUM 4.02013

    The Jenkins Plugin for SonarQube 3.7 and earlier allows remote authenticated users to obtain sensitive information (cleartext passwords) by reading the value in the sonar.sonarPassword parameter from …

Materials

0

No datasheets, whitepapers, case studies, videos, or demos linked yet.

Other Application Security (ASPM) products

see all →
  • AI SAST · Arnica
  • Acunetix Web Application & API Security · Acunetix
  • Adronite · Adronite
  • Almanax · Almanax
  • Amplify Security Fix Your Code · Amplify Security
  • Anchore Anchore Enterprise · Anchore
  • Apiiro AI SAST · Apiiro
  • Apiiro ASPM Platform · Apiiro