SonarQube 8.4.2.36762 allows remote attackers to discover cleartext SMTP,
SVN, and GitLab credentials via the api/settings/values URI.
id: CVE-2020-27986
info:
name: SonarQube - Authentication Bypass
author: pikpikcu
severity: h
...