Description
This affects all versions of package sonar-wrapper. The injection point is located in lib/sonarRunner.js.
Remediation
References
https://security.snyk.io/vuln/SNYK-JS-SONARWRAPPER-1050980
Related Vulnerabilities
CVE-2020-13128 Vulnerability in maven package com.googlecode.gwtupload:gwtupload-project
CVE-2023-35166 Vulnerability in maven package org.xwiki.platform:xwiki-platform-help-ui
CVE-2022-29647 Vulnerability in maven package net.mingsoft:ms-mcms
CVE-2022-3509 Vulnerability in maven package com.google.protobuf:protobuf-java
CVE-2020-28502 Vulnerability in maven package org.webjars.npm:xmlhttprequest