The official sonarqube docker images before alpine (Alpine specific) contain a blank password for a root user. System using the sonarqube docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Sonarqube_docker_image | Sonarsource | 4.5.7 (including) | 4.5.7 (including) |
Sonarqube_docker_image | Sonarsource | 5.5 (including) | 5.5 (including) |
Sonarqube_docker_image | Sonarsource | 5.6 (including) | 5.6 (including) |
Sonarqube_docker_image | Sonarsource | 5.6.1 (including) | 5.6.1 (including) |
Sonarqube_docker_image | Sonarsource | 5.6.2 (including) | 5.6.2 (including) |
Sonarqube_docker_image | Sonarsource | 5.6.3 (including) | 5.6.3 (including) |
Sonarqube_docker_image | Sonarsource | 5.6.4 (including) | 5.6.4 (including) |
Sonarqube_docker_image | Sonarsource | 5.6.5 (including) | 5.6.5 (including) |
Sonarqube_docker_image | Sonarsource | 5.6.7 (including) | 5.6.7 (including) |
Sonarqube_docker_image | Sonarsource | 6.0 (including) | 6.0 (including) |
Sonarqube_docker_image | Sonarsource | 6.1 (including) | 6.1 (including) |
Sonarqube_docker_image | Sonarsource | 6.2 (including) | 6.2 (including) |
Sonarqube_docker_image | Sonarsource | 6.3 (including) | 6.3 (including) |
Sonarqube_docker_image | Sonarsource | 6.3.1 (including) | 6.3.1 (including) |
Sonarqube_docker_image | Sonarsource | 6.4 (including) | 6.4 (including) |
Sonarqube_docker_image | Sonarsource | 6.5 (including) | 6.5 (including) |
Sonarqube_docker_image | Sonarsource | 6.6 (including) | 6.6 (including) |
Sonarqube_docker_image | Sonarsource | 6.7 (including) | 6.7 (including) |
Sonarqube_docker_image | Sonarsource | 6.7.1 (including) | 6.7.1 (including) |
Sonarqube_docker_image | Sonarsource | 6.7.2 (including) | 6.7.2 (including) |
Sonarqube_docker_image | Sonarsource | 6.7.3 (including) | 6.7.3 (including) |
Sonarqube_docker_image | Sonarsource | 6.7.4 (including) | 6.7.4 (including) |
Sonarqube_docker_image | Sonarsource | 6.7.5 (including) | 6.7.5 (including) |
Sonarqube_docker_image | Sonarsource | 7.0 (including) | 7.0 (including) |
Sonarqube_docker_image | Sonarsource | 7.1 (including) | 7.1 (including) |
Sonarqube_docker_image | Sonarsource | lts (including) | lts (including) |
As data is migrated to the cloud, if access does not require authentication, it can be easier for attackers to access the data from anywhere on the Internet.