CVE-2017-1000390: Jenkins Multijob
Medium severity, CVSS 4.3. EPSS: 0.7% chance of exploitation in the next 30 days.
Jenkins Multijob plugin version 1.25 and earlier did not check permissions in the Resume Build action, allowing anyone with Job/Read permission to resume the build.
Affected products
- Jenkins Multijob: up to and including 1.25
Published 2018-01-26. Last modified 2026-06-17.