ZeroHour

CVE-2020-2098

CVSS 3.1
8.8 high
EPSS
1%p61
Published
()
Modified
Description

A cross-site request forgery vulnerability in Jenkins Sounds Plugin 0.5 and earlier allows attacker to execute arbitrary OS commands as the OS user account running Jenkins.

Vendors
jenkins
Products
sounds
Weakness
CWE-352
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.