Executive brief
The Jenkins Multijob Plugin, which allows users to manage complex build hierarchies, contains a security flaw that could allow an unauthorized person to interfere with software build processes. By tricking a logged-in administrator into clicking a malicious link, an attacker can force the system to resume failed software builds without authorization. This could lead to unintended resource consumption or the execution of build steps that were meant to remain stopped.
Technical details
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Jenkins Multijob Plugin versions 662.vd2e0001f6b_b_d and earlier. The vulnerability is caused by an HTTP endpoint used for resuming failed builds that fails to require POST requests, allowing state-changing actions to be triggered via GET requests. An attacker can exploit this by inducing a victim with the necessary permissions to follow a specially crafted link or visit a malicious website. Successful exploitation allows the attacker to resume failed Multijob builds. The issue is resolved in version 669.v9d96a_d9c71b_0 by enforcing POST request requirements for the affected endpoint.
Affected products
- Jenkins Multijob Plugin <= 662.vd2e0001f6b_b_d
Timeline
- 2026-05-27: disclosed: Initial advisory publication
- 2026-05-27: patched: Fixed in version 669.v9d96a_d9c71b_0