PT-2020-15303 · Jenkins · Jenkins Sounds Plugin+1

·

CVE-2020-2097

·

Published

2020-01-15

·

Updated

2023-10-25

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Jenkins Sounds Plugin version 0.5 and earlier
Description The issue allows attackers with Overall/Read access to execute arbitrary OS commands as the OS user account running Jenkins, due to a lack of permission checks in URLs performing form validation.
Recommendations For Jenkins Sounds Plugin version 0.5 and earlier, update to a version that includes the necessary permission checks to prevent arbitrary OS command execution.

Fix

Incorrect Authorization

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-2097
GHSA-H8W6-C53G-53VV

Affected Products

Jenkins
Jenkins Sounds Plugin