jenkins-multijob-plugin is vulnerable to Cross-Site Request Forgery (CSRF)
88
High Risk
A form validation endpoint does not require POST requests, so it is vulnerable to cross-site request forgery. An attacker can trick a victim's browser into calling that endpoint and run arbitrary code in the Jenkins controller JVM. The fix requires POST for the affected endpoint.
You are affected if you are using a version that falls within the vulnerable range and authenticated users can be induced to visit attacker-controlled pages while logged into Jenkins.
jenkins-multijob-plugin is vulnerable to Cross-Site Request Forgery (CSRF) in versions 0.0.1 - 669.
Upgrade the org.jenkins-ci.plugins:jenkins-multijob-plugin library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant