Impact
This vulnerability allows users with Item/Create or Item/Configure permissions to inject and run arbitrary Groovy scripts in the Jenkins controller’s Java Virtual Machine. Because the plugin’s scripting features bypass the Script Security Plugin, an attacker can execute code with the full privileges of the Jenkins service, potentially compromising the entire system. The impact encompasses complete denial of confidentiality, integrity, and availability of the affected Jenkins instance.
Affected Systems
The Jenkins Multijob Plugin versions 669.v9d96a_d9c71b_0 and earlier are affected. Users deploying these versions on Jenkins should review plugin versions and consider upgrading to a release where Groovy scripting is enforced through the Script Security Plugin.
Risk and Exploitability
The vulnerability is severe, as it permits remote code execution without requiring network-level access; it can be triggered by any user who can create or configure a multijob project. The CVSS score is not provided, but the lack of a Script Security check implies a high exploitation probability. The EPSS is unavailable and the issue is not listed in the CISA KEV catalog, yet the potential damage warrants immediate attention.
OpenCVE Enrichment