T09 · Insecure Skill Coding Practices
- Location
references/metrics.md:63- Finding
Authentication Token Transmitted over Plaintext HTTP
- Content
View full analysis
Vulnerability Details
File Location:
references/metrics.md:63
Vulnerability Type: Credential exposure over an unencrypted transport
Risk Level: MediumVulnerable Code
bash curl -u token: "http://sonarqube/api/measures/component?component=my-service&metricKeys=complexity,duplicated_lines_density,ncloc,function_complexity,coverage"Technical Analysis
The documented command supplies a SonarQube authentication token through HTTP Basic authentication while connecting over plaintext HTTP. Basic authentication only encodes the credential; it does not encrypt it. Without TLS, the authorization header and returned architecture metrics are exposed to interception and modification.
A user following this integration example on an untrusted or compromised network could disclose the SonarQube token to an on-path attacker. The use of plaintext HTTP also provides no reliable server authentication, allowing an attacker to impersonate the service and collect the supplied credential.
Attack Path
- A user follows the documented SonarQube metric-collection example.
curlsends the Basic authorization header to the endpoint over plaintext HTTP.- An attacker with access to the network path captures the request or redirects it to an attacker-controlled endpoint.
- The attacker recovers the token and may use it against the SonarQube instance according to the token's assigned permissions.
- Alternatively, the attacker modifies metric responses, corrupting architecture-health reports and governance decisions.
Impact Assessment
The maximum privileges obtained are those assigned to the exposed SonarQube token. Depending on its scope, an attacker may gain access to source-quality findings, project metadata, vulnerability reports, or administrative operations.
The affected scope includes users who copy the example without replacing HTTP with an authenticated TLS connection. Metric integrity is also at risk because an on-path attacker ...[truncated 61 chars]
- Remediation
View remediation
Remediation Suggestions
- Require HTTPS with certificate verification:
bash curl --fail --show-error --silent \ -u "${SONAR_TOKEN}:" \ "https://sonarqube.example.com/api/measures/component?component=my-service&metricKeys=complexity,duplicated_lines_density,ncloc,function_complexity,coverage"- Retrieve the token from a protected environment variable or secret manager rather than embedding it in the command or documentation.
- Use a dedicated, read-only, least-privilege token restricted to the required projects and API operations.
- Rotate any token that may already have been sent over plaintext HTTP.
- Prohibit insecure TLS bypass options such as
curl -k. - Document secure token handling, including shell-history risks, log redaction, expiration, and rotation.
- Prefer a configuration mechanism that validates the URL scheme and rejects non-HTTPS endpoints when credentials are present.
