Description
This affects all versions of package sonar-wrapper. The injection point is located in lib/sonarRunner.js.
Remediation
References
https://security.snyk.io/vuln/SNYK-JS-SONARWRAPPER-1050980
Related Vulnerabilities
CVE-2018-3729 Vulnerability in npm package localhost-now
CVE-2022-41918 Vulnerability in maven package org.opensearch.plugin:opensearch-security
CVE-2023-29210 Vulnerability in maven package org.xwiki.platform:xwiki-platform-notifications-ui
CVE-2022-31190 Vulnerability in maven package org.dspace:dspace-xmlui