CVE-2013-5676: Sonarsource Jenkins Plugin
Medium severity, CVSS 4.0. EPSS: 5% chance of exploitation in the next 30 days.
The Jenkins Plugin for SonarQube 3.7 and earlier allows remote authenticated users to obtain sensitive information (cleartext passwords) by reading the value in the sonar.sonarPassword parameter from jenkins/configure.
Affected products
- Sonarsource Jenkins Plugin: affected versions not specified
Published 2013-12-13. Last modified 2026-06-16.