CVE-2020-28443: Sonar-Wrapper Project Sonar-Wrapper

Critical severity, CVSS 9.8. EPSS: 1.3% chance of exploitation in the next 30 days.

This affects all versions of package sonar-wrapper. The injection point is located in lib/sonarRunner.js.

Affected products

Published 2022-07-25. Last modified 2026-06-17.