Vulnerability Details CVE-2020-2097
Jenkins Sounds Plugin 0.5 and earlier does not perform permission checks in URLs performing form validation, allowing attackers with Overall/Read access to execute arbitrary OS commands as the OS user account running Jenkins.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 29.2%
CVSS Severity
CVSS v3 Score 8.8
CVSS v2 Score 6.5
Products affected by CVE-2020-2097
-
cpe:2.3:a:jenkins:sounds:-
-
cpe:2.3:a:jenkins:sounds:0.1
-
cpe:2.3:a:jenkins:sounds:0.2
-
cpe:2.3:a:jenkins:sounds:0.3
-
cpe:2.3:a:jenkins:sounds:0.4
-
cpe:2.3:a:jenkins:sounds:0.4.1
-
cpe:2.3:a:jenkins:sounds:0.4.2
-
cpe:2.3:a:jenkins:sounds:0.4.3
-
cpe:2.3:a:jenkins:sounds:0.5