Cross-Site Request Forgery in Jenkins Dynatrace Application Monitoring Plugin
CVE-2019-10462

8.1HIGH

What is CVE-2019-10462?

A cross-site request forgery vulnerability was identified in the Jenkins Dynatrace Application Monitoring Plugin version 2.1.3 and earlier. This security flaw allows attackers to use attacker-specified credentials to connect to a URL of their choice. As a result, malicious actors can exploit this vulnerability to perform unauthorized actions, posing significant risks to user data and system integrity.

Affected Version(s)

Jenkins Dynatrace Application Monitoring Plugin 2.1.3 and earlier

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.