sonar-wrapper@0.1.2 vulnerabilities

sonar-wrapper standalone scanner

Direct Vulnerabilities

Known vulnerabilities in the sonar-wrapper package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • C
Command Injection

sonar-wrapper is a package that wraps SonarQube Scanner as a node module.

Affected versions of this package are vulnerable to Command Injection. The injection point is located in lib/sonarRunner.js.

How to fix Command Injection?

There is no fixed version for sonar-wrapper.

*