Skip to main content

Vendor/product archive

jenkins / sounds CVEs

Beta · best-effort

2 CVEs tagged to jenkins / sounds0 Critical, 2 High, 0 Medium, 0 Low, 0 Unrated.

CVE-2020-2098

Published Jan 15, 2020

A cross-site request forgery vulnerability in Jenkins Sounds Plugin 0.5 and earlier allows attacker to execute arbitrary OS commands as the OS user account running Jenkins.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-2097

Published Jan 15, 2020

Jenkins Sounds Plugin 0.5 and earlier does not perform permission checks in URLs performing form validation, allowing attackers with Overall/Read access to execute arbitrary OS co…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-2 of 2 CVEsPage 1 of 1