Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not restrict or transform the characters that can be inserted from user-specified content in log messages, allowing attackers able to control log message contents to insert line break characters, followed by forged log messages that may mislead administrators reviewing log output.
Metrics
Affected Vendors & Products
References
History
Thu, 18 Sep 2025 12:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Jenkins
Jenkins jenkins |
|
Vendors & Products |
Jenkins
Jenkins jenkins |
Thu, 18 Sep 2025 00:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Title | jenkins: Log message injection vulnerability | |
Weaknesses | CWE-117 | |
References |
| |
Metrics |
threat_severity
|
cvssV3_1
|
Wed, 17 Sep 2025 13:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not restrict or transform the characters that can be inserted from user-specified content in log messages, allowing attackers able to control log message contents to insert line break characters, followed by forged log messages that may mislead administrators reviewing log output. | |
References |
|

Status: PUBLISHED
Assigner: jenkins
Published: 2025-09-17T13:17:48.559Z
Updated: 2025-09-17T13:17:48.559Z
Reserved: 2025-09-16T16:16:05.526Z
Link: CVE-2025-59476

No data.

Status : Awaiting Analysis
Published: 2025-09-17T14:15:41.297
Modified: 2025-09-17T14:18:55.093
Link: CVE-2025-59476
