Description
This affects all versions of package sonar-wrapper. The injection point is located in lib/sonarRunner.js.
Remediation
References
https://security.snyk.io/vuln/SNYK-JS-SONARWRAPPER-1050980
Related Vulnerabilities
CVE-2015-8862 Vulnerability in maven package org.webjars.npm:mustache
CVE-2020-6459 Vulnerability in maven package org.webjars.npm:electron
CVE-2017-16101 Vulnerability in npm package serverwg
CVE-2021-38296 Vulnerability in maven package org.apache.spark:spark-core
CVE-2021-21353 Vulnerability in maven package org.webjars.npm:pug