SonarQube 8.4.2.36762 allows remote attackers to discover cleartext SMTP, SVN, and GitLab credentials via the api/settings/values URI.
View the template here CVE-2020-27986.yaml
References:
https://csl.com.co/sonarqube-auditando-al-auditor-parte-i/