-
Notifications
You must be signed in to change notification settings - Fork 0
Closed
Labels
enhancementNew feature or requestNew feature or request
Description
Upgrade SonarSource/sonarqube-scan-action to version 5.3.1 or later
Description:
A command injection vulnerability was discovered in the SonarQube Scan GitHub Action that allows untrusted input arguments to be processed without proper sanitization. Arguments sent to the action are treated as shell expressions, allowing potential execution of arbitrary commands.
References:
Metadata
Metadata
Assignees
Labels
enhancementNew feature or requestNew feature or request