{"id":"GHSA-m643-2pfv-xwm8","summary":"Exposure of Sensitive Information to an Unauthorized Actor in SonarSource SonarQube API","details":"A vulnerability in the API of SonarSource SonarQube before 7.5 could allow an authenticated user to discover sensitive information such as valid user-account logins in the web application. The vulnerability occurs because of improperly configured access controls that cause the API to return the externalIdentity field to non-administrator users. The attacker could use this information in subsequent attacks against the system.","aliases":["CVE-2018-19413"],"modified":"2024-03-04T22:46:21.813592Z","published":"2022-05-14T01:43:42Z","database_specific":{"nvd_published_at":"2018-12-14T15:29:00Z","cwe_ids":["CWE-200"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2022-06-28T23:26:18Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2018-19413"},{"type":"WEB","url":"https://github.com/SonarSource/sonarqube/commit/7b567ba3d15ed7dd0b0bba0330686487e35af85c"},{"type":"WEB","url":"https://jira.sonarsource.com/browse/SONAR-11305"},{"type":"WEB","url":"http://packetstormsecurity.com/files/150496/SonarSource-SonarQube-7.3-Information-Disclosure.html"}],"affected":[{"package":{"name":"org.sonarsource.sonarqube:sonar-plugin-api","ecosystem":"Maven","purl":"pkg:maven/org.sonarsource.sonarqube/sonar-plugin-api"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.5"}]}],"versions":["5.2","5.2-RC2","5.2-RC3","5.2-RC4","5.3","5.3-RC1","5.3-RC2","5.4","5.4-RC1","5.4-RC2","5.4-RC3","5.4-RC4","5.5","5.5-RC1","5.5-RC2","5.6","5.6-RC1","5.6-RC2","5.6.1","5.6.2","5.6.3","5.6.4","5.6.5","5.6.6","5.6.7","6.0","6.0-RC1","6.0-RC2","6.1","6.1-RC1","6.1-RC2","6.2","6.2-RC1","6.2-RC3","6.2.1","6.3","6.3-RC4","6.3.1","6.4","6.4-RC1","6.4-RC2","6.4-RC3","6.5","6.5-RC1","6.5-RC2","6.6","6.6-RC1","6.7","6.7-RC1","6.7.1","6.7.3","6.7.4","6.7.5","6.7.6","6.7.7","7.0","7.0-RC1","7.1","7.2","7.2.1","7.3","7.3-alpha1","7.4","7.4-alpha2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-m643-2pfv-xwm8/GHSA-m643-2pfv-xwm8.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"}]}