Executive brief
Black Duck Coverity Connect, a platform used by software development teams to manage code quality and security issues, contains a vulnerability that allows unauthorized users to bypass security checks. By sending a specially crafted web request, an attacker can gain access to sensitive data within the system without needing a username or password. This could lead to the exposure of proprietary source code analysis results and other internal development data.
Technical details
An authentication and authorization bypass vulnerability exists in the Spring Security implementation within Black Duck Coverity Connect. The flaw resides in certain API endpoints that fail to properly enforce access controls when processing specially crafted HTTP requests. An unauthenticated remote attacker can exploit this to bypass security filters and access internal data. The vulnerability affects versions 2023.6.0 through 2026.3.0. While the CVSS 4.0 score is high (9.2), the attack complexity is rated as high with specific conditions required for successful exploitation. Users are advised to upgrade to version 2026.6.0 or later to remediate the issue.
Affected products
- Black Duck Coverity Connect 2023.6.0 to 2026.3.0
Timeline
- 2026-07-29: advisory: Initial disclosure by Synopsys/Black Duck
- 2026-07-29: disclosed