This repository was archived by the owner on Jan 19, 2023. It is now read-only.

Description
Vulnerability URL
Provide the URL to the vulnerability. For example:
https://ossindex.sonatype.org/vulnerability/sonatype-2016-0594
Component URL
Provide the URL to the component. For example:
https://ossindex.sonatype.org/component/pkg:nuget/DeveloperForce.Force@2.1.0
Description
The flagged pull request in the vulnerability report does show a sql-like string being formatted. But that string is consumed as an API query parameter in calling salesforce. So the outcome would more likely be a mangled query.
Looks like a false positive.