Lucene search

K
osvGoogleOSV:GHSA-H8W6-C53G-53VV
HistoryMay 24, 2022 - 5:06 p.m.

Missing permission checks in Jenkins Sounds Plugin allow OS command execution

2022-05-2417:06:23
Google
osv.dev
12
jenkins
sounds plugin
permission checks
os command execution

EPSS

0.001

Percentile

42.8%

Jenkins Sounds Plugin 0.5 and earlier does not perform permission checks in URLs performing form validation, allowing attackers with Overall/Read access to execute arbitrary OS commands as the OS user account running Jenkins.

EPSS

0.001

Percentile

42.8%

Related for OSV:GHSA-H8W6-C53G-53VV