CVE-2019-10462
published 2019-10-23CVE-2019-10462: A cross-site request forgery vulnerability in Jenkins Dynatrace Application Monitoring Plugin 2.1.3 and earlier allowed attackers to connect to an…
high8.1CVSS 3.1
AVNACLPRNUIRSUCHIHAN
A cross-site request forgery vulnerability in Jenkins Dynatrace Application Monitoring Plugin 2.1.3 and earlier allowed attackers to connect to an attacker-specified URL using attacker-specified credentials.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jenkins | bitbucket_oauth_plugin | — | — |
| jenkins | deploy_weblogic_plugin | — | — |
| jenkins | dynatrace_application_monitoring | <= 2.1.3 | — |
| jenkins | dynatrace_application_monitoring_plugin | — | — |
| jenkins | global_post_script_plugin | — | — |
| jenkins | ids_in_libvirt_agents_plugin | — | — |
| jenkins | ids_to_allow_users_configuring_the_plugin | — | — |
| jenkins | libvirt_agents_plugin | — | — |
| jenkins | mattermost_notification_plugin | — | — |
| jenkins | sonar_gerrit_plugin | — | — |
| jenkins | zulip_plugin | — | — |
| jenkins_project | jenkins_dynatrace_application_monitoring_plugin | — | — |