CVE-2020-2098

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
15/01/2020
Last modified:
25/10/2023

Description

A cross-site request forgery vulnerability in Jenkins Sounds Plugin 0.5 and earlier allows attacker to execute arbitrary OS commands as the OS user account running Jenkins.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:jenkins:sounds:*:*:*:*:*:jenkins:*:* 0.5 (including)


References to Advisories, Solutions, and Tools