Description
A cross-site request forgery vulnerability in Jenkins Sounds Plugin 0.5 and earlier allows attacker to execute arbitrary OS commands as the OS user account running Jenkins.
Remediation
References
https://jenkins.io/security/advisory/2020-01-15/#SECURITY-814
Related Vulnerabilities
CVE-2023-3348 Vulnerability in npm package wrangler
CVE-2020-17518 Vulnerability in maven package org.apache.flink:flink-runtime_2.12
CVE-2014-2065 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2018-1297 Vulnerability in maven package org.apache.jmeter:apachejmeter
CVE-2023-35926 Vulnerability in npm package @backstage/plugin-scaffolder-backend