CyberRota Analysis
AI-GeneratedThe Jenkins Multijob Plugin versions up to 669.v9d96a_d9c71b_0 are vulnerable due to insufficient integration with the Script Security Plugin, enabling attackers with Item/Create or Item/Configure permissions to execute arbitrary Groovy scripts on the Jenkins controller JVM. This vulnerability poses a significant risk as it allows unauthorized code execution, potentially compromising the entire Jenkins environment. Organizations using affected versions of Jenkins should prioritize patching to mitigate the risk of exploitation.
Original NVD Description
Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier provides Groovy scripting features that do not integrate with Script Security Plugin, allowing attackers with Item/Create or Item/Configure permission to execute arbitrary code in the context of the Jenkins controller JVM.