CVE-2020-2097: High severity Jenkins Sounds Jenkins vulnerability
Published Jan 15, 2020
·Updated
Jenkins Sounds Plugin 0.5 and earlier does not perform permission checks in URLs performing form validation, allowing attackers with Overall/Read access to execute arbitrary OS commands as the OS user account running Jenkins.
Affected Software
1 affected component
Jenkins Sounds Jenkins<=0.5
Event History
Jan 15, 2020
CVE Published
via MITRE·03:15 PM
Data Sourced
via MITRE·03:15 PM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2020-2097?
CVE-2020-2097 is rated as a high severity vulnerability due to its potential to allow arbitrary OS command execution.
2
How do I fix CVE-2020-2097?
To fix CVE-2020-2097, update the Jenkins Sounds Plugin to version 0.6 or later.
3
What versions of the Jenkins Sounds Plugin are affected by CVE-2020-2097?
Versions 0.5 and earlier of the Jenkins Sounds Plugin are affected by CVE-2020-2097.
4
Who can exploit CVE-2020-2097?
Attackers with Overall/Read access can exploit CVE-2020-2097 to execute arbitrary OS commands.
5
What does CVE-2020-2097 allow an attacker to do?
CVE-2020-2097 allows an attacker to execute arbitrary OS commands as the OS user account running Jenkins.