CVE-2020-2098: CSRF
Published Jan 15, 2020
·Updated
A cross-site request forgery vulnerability in Jenkins Sounds Plugin 0.5 and earlier allows attacker to execute arbitrary OS commands as the OS user account running Jenkins.
Affected Software
1 affected component
Jenkins Sounds Jenkins<=0.5
Event History
Jan 15, 2020
CVE Published
via MITRE·03:15 PM
Data Sourced
via MITRE·03:15 PM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2020-2098?
CVE-2020-2098 is classified as a critical vulnerability due to its potential to allow an attacker to execute arbitrary OS commands.
2
How do I fix CVE-2020-2098?
To fix CVE-2020-2098, update the Jenkins Sounds Plugin to version 0.6 or later.
3
What systems are affected by CVE-2020-2098?
CVE-2020-2098 affects Jenkins Sounds Plugin versions 0.5 and earlier.
4
What type of vulnerability is CVE-2020-2098?
CVE-2020-2098 is a cross-site request forgery vulnerability.
5
What actions can an attacker perform due to CVE-2020-2098?
An attacker can exploit CVE-2020-2098 to execute arbitrary OS commands as the OS user account running Jenkins.