Security Advisory: SonarQube Scanner GitHub Action

IMHO there is no point in not disclosing this right away when it’s already in plain sight:

There are even test cases in the repo that show exactly how to exploit the vulnerability: a potential command injection caused by unsanitized arguments.

Since this is an open-source repository, a bad actor could figure out the vulnerability in minutes. In this case, withholding information does more harm than good by not being completely transparent with customers from the start.

4 Likes