Impact
The Jenkins Multijob Plugin versions 669.v9d96a_d9c71b_0 and earlier expose a Groovy scripting interface that does not integrate with the Script Security Plugin, allowing users with Item/Create or Item/Configure permissions to run arbitrary Groovy code inside the Jenkins controller JVM. This flaw gives the attacker full control over the Jenkins instance, enabling data exfiltration, configuration tampering, and complete system compromise, thus affecting confidentiality, integrity, and availability.
Affected Systems
Jenkins Multijob Plugin versions 669.v9d96a_d9c71b_0 and all earlier releases are affected. Any Jenkins deployment that has these plugin versions installed is at risk and should be evaluated for an upgrade.
Risk and Exploitability
An attacker who can create or configure a multijob project can exploit this vulnerability; no external network access is required – the attack is triggered purely by legitimate Jenkins user privileges. The CVSS score of 8.8 indicates high severity. The EPSS score is not available and the issue is not listed in the CISA KEV catalog. The attack vector is inferred from the supplied description, indicating an in‑Jenkins local privilege exploitation scenario.
OpenCVE Enrichment