CVE-2019-1003022

Cross-Site Request Forgery (CSRF) in maven/org.jvnet.hudson.plugins/monitoring

Identifiers

GHSA-hw83-jpxr-g225, CVE-2019-1003022

Package Slug

maven/org.jvnet.hudson.plugins/monitoring

Vulnerability

Cross-Site Request Forgery (CSRF)

Description

A denial of service vulnerability exists in Jenkins Monitoring Plugin 1.74.0 and earlier in PluginImpl.java that allows attackers to kill threads running on the Jenkins master.

Affected Versions

All versions up to 1.74.0

Solution

Upgrade to version 1.75.0 or above.

Last Modified

2024-01-31

source