CVE-2017-1000390: Jenkins Multijob

Medium severity, CVSS 4.3. EPSS: 0.7% chance of exploitation in the next 30 days.

Jenkins Multijob plugin version 1.25 and earlier did not check permissions in the Resume Build action, allowing anyone with Job/Read permission to resume the build.

Affected products

  • Jenkins Multijob: up to and including 1.25

Published 2018-01-26. Last modified 2026-06-17.