GHSA-pj84-qjm3-77mg
GitHub Security Advisory
Jenkins Pipeline: Multibranch Plugin vulnerable to OS Command Injection
✓ GitHub Reviewed
HIGH
Has CVE
Advisory Details
Jenkins Pipeline: Multibranch Plugin 706.vd43c65dec013 and earlier uses distinct checkout directories per SCM for the readTrusted step, allowing attackers with Item/Configure permission to invoke arbitrary OS commands on the controller through crafted SCM contents.
Affected Packages
Maven
org.jenkins-ci.plugins.workflow:workflow-multibranch
Affected versions:
0
(fixed in 707.v71c3f0a_6ccdb)
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: August 25, 2025 6:33 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.