Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2013-5676

22
FAUCET Score

CVE-2013-5676 describes a sensitive information disclosure vulnerability in the Jenkins Plugin for SonarQube versions 3.7 and earlier. Authenticated attackers could read cleartext passwords by accessing the 'sonar.sonarPassword' parameter within the Jenkins configuration. With a CVSS score of 4.0, this vulnerability is of medium severity, requiring network access and authentication to achieve partial confidentiality impact. While not actively exploited in the wild or on the CISA KEV catalog, public exploit code exists on ExploitDB, but there is no evidence of Metasploit or Nuclei modules, nor significant community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:a:sonarsource:jenkins_plugin:-:-:-:*:-:sonarqube:*:*

CVSS Data

CVSS version used by this source: 2.0

4.0MEDIUM

AV:N/AC:L/Au:S/C:P/I:N/A:N

Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
Access Vector
NETWORK
Access Complexity
LOW
Authentication
SINGLE
Exploitability Score
8.0
Impact Score
2.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
4.99%
Probability of exploitation in next 30 days
EPSS Percentile
91.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
ExploitDB: EDB-30409 · Dec 18, 2013
This CVE's current EPSS score of 0.0499 is in the 97th percentile among its peer group of 21,954 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (2)

mavenGHSA-3x9h-3p7m-33m7medium

Jenkins SonarQube Plugin Stores Passwords in Cleartext

May 17, 2022
redhatCVE-2013-5676Low

Plugin: Plain Text Password Disclosure via configuration parameters

Dec 6, 2013

References

seclists.org / fulldisclosure/2013/Dec/37
osvdb.org / 100666