Executive brief
Coverity Connect is a centralized management console used by software development teams to track and manage code quality and security issues. A vulnerability in its web-based communication interface allows an authorized user to execute unauthorized database commands. This could lead to the exposure of sensitive proprietary code data, modification of security records, or disruption of the management platform.
Technical details
A SQL injection vulnerability (CWE-89) exists within the SOAP API component of Coverity Connect. The flaw is caused by improper neutralization of special elements in SQL commands within the API's request handling logic. An authenticated attacker with network access to the SOAP API can send specially crafted payloads to bypass intended query logic. Successful exploitation allows for full read access to the underlying database, potential data modification, and the execution of unauthorized administrative commands. The vulnerability affects versions 2024.6.0 through 2026.3.0; users are advised to upgrade to version 2026.6.0 or later.
Affected products
- Black Duck Coverity Connect 2024.6.0 through 2026.3.0
Timeline
- 2026-07-29: advisory: Initial advisory published by Synopsys/Black Duck