vendor:
SonarQube
by:
Velayutham Selvaraj
7.2
CVSS
HIGH
Unquoted Service Path
22
CWE
Product Name: SonarQube
Affected Version From: 8.3.1
Affected Version To: 8.3.1
Patch Exists: NO
Related CWE: N/A
CPE: a:sonarqube:sonarqube:8.3.1
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10 64bit(EN)
2020
Sonar Qube 8.3.1 – ‘SonarQube Service’ Unquoted Service Path
When a service is created whose executable path contains spaces and isn't enclosed within quotes, leads to a vulnerability known as Unquoted Service Path which allows a user to gain SYSTEM privileges.
Mitigation:
Enclose the service path within quotes.