OS Command Injection in Sounds - CVE-2020-2097
Published: January 16, 2020
Sounds
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary shell commands on the target system.
The vulnerability exists due to the affected software does not perform permission checks in URLs performing form validation. A remote user with Overall/Read access can execute arbitrary OS commands as the OS user account running Jenkins.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.