CVE-2020-2097
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 1.2%
exploitation probability
1.2%top 33% of all CVEs
observed exploitation
nono source reports it
Jenkins Sounds Plugin 0.5 and earlier does not perform permission checks in URLs performing form validation, allowing attackers with Overall/Read access to execute arbitrary OS commands as the OS user account running Jenkins.
Affected products
Jenkins project · Jenkins Sounds Plugin