GHSA-wr4v-3f2h-6hhh

Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/07/GHSA-wr4v-3f2h-6hhh/GHSA-wr4v-3f2h-6hhh.json
Aliases
  • CVE-2020-28443
Published
2022-07-26T00:01:05Z
Modified
2022-08-06T05:18:26Z
Details

A command injection vulnerability affects all versions of package sonar-wrapper. The injection point is located in lib/sonarRunner.js.

References

Affected packages

npm / sonar-wrapper

sonar-wrapper

Affected ranges

Type
SEMVER
Events
Introduced
0

Affected versions

Database specific

{
    "last_known_affected_version_range": "<= 0.1.3"
}