jenkins-multijob-plugin is vulnerable to Remote Code Execution (RCE)
84
High Risk
Groovy scripting features in Multijob do not integrate with Script Security Plugin sandboxing. An attacker with Item/Create or Item/Configure permission can run arbitrary code in the Jenkins controller JVM. The fix runs those scripts through Script Security Plugin sandboxing.
You are affected if you are using a version that falls within the vulnerable range and users with Item/Create or Item/Configure permission can edit Multijob Groovy scripts.
jenkins-multijob-plugin is vulnerable to Remote Code Execution (RCE) in versions 0.0.1 - 669.
Upgrade the org.jenkins-ci.plugins:jenkins-multijob-plugin library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant