CyberRota Analysis
This is a high severity vulnerability with a CVSS score of 7.5. It affects GitLab. Its EPSS score suggests a 16.2% probability of exploitation in the next 30 days. It may be remotely exploitable.
CVE
CVE-2020-27986
Severity
HIGH
CVSS
7.5
EPSS
16.18%
GitLab
Original NVD Description
SonarQube 8.4.2.36762 allows remote attackers to discover cleartext SMTP, SVN, and GitLab credentials via the api/settings/values URI. NOTE: reportedly, the vendor's position for SMTP and SVN is "it is the administrator's responsibility to configure it.
Related CVEs
Other vulnerabilities affecting the same vendor(s)