Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not restrict or transform the characters that can be inserted from user-specified content in log messages, allowing attackers able to control log message contents to insert line break characters, followed by forged log messages that may mislead administrators reviewing log output.
Metrics
Affected Vendors & Products
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 17 Sep 2025 13:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not restrict or transform the characters that can be inserted from user-specified content in log messages, allowing attackers able to control log message contents to insert line break characters, followed by forged log messages that may mislead administrators reviewing log output. | |
References |
|

Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2025-09-17T13:17:48.559Z
Reserved: 2025-09-16T16:16:05.526Z
Link: CVE-2025-59476

No data.

Status : Awaiting Analysis
Published: 2025-09-17T14:15:41.297
Modified: 2025-09-17T14:18:55.093
Link: CVE-2025-59476

No data.

No data.