Impact
The Jenkins Multijob Plugin contains a cross‑site request forgery flaw that permits attackers to cause the Jenkins controller to run arbitrary code. By forging a request from a victim’s browser or directly sending malicious payloads, an attacker can execute code with the same privileges as the Jenkins service. The weakness is a classic CSRF that ends in remote code execution, jeopardizing confidentiality, integrity and availability of the Jenkins environment.
Affected Systems
The vulnerability affects the Jenkins Multijob Plugin versions 669.v9d96a_d9c71b_0 and earlier. Systems running Jenkins with this plugin without an upgraded version are at risk. The affected product is the Multijob Plugin distributed by the Jenkins Project.
Risk and Exploitability
The CVSS score is 8.8, but the exploitation requires the ability to drive a request to the vulnerable Jenkins instance, typically via an authenticated or victim's browser exploited with CSRF. Because the exploit is dependent on the presence of the plugin and the lack of CSRF tokens, the risk is significant for setups where the plugin is enabled. No EPSS value is available and the flaw is not listed in CISA KEV, however the potential for arbitrary code execution makes it a high‑severity issue. The attack vector is inferred to be a CSRF attack that tricks a trusted browser into sending malicious requests to the Jenkins controller.
OpenCVE Enrichment