Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not restrict or transform the characters that can be inserted from user-specified content in log messages, allowing attackers able to control log message contents to insert line break characters, followed by forged log messages that may mislead administrators reviewing log output.
Metrics
Affected Vendors & Products
References
History
Thu, 02 Oct 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:jenkins:jenkins:*:*:*:*:-:*:*:* cpe:2.3:a:jenkins:jenkins:*:*:*:*:lts:*:*:* |
Thu, 25 Sep 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 18 Sep 2025 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jenkins
Jenkins jenkins |
|
| Vendors & Products |
Jenkins
Jenkins jenkins |
Thu, 18 Sep 2025 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | jenkins: Log message injection vulnerability | |
| Weaknesses | CWE-117 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Wed, 17 Sep 2025 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not restrict or transform the characters that can be inserted from user-specified content in log messages, allowing attackers able to control log message contents to insert line break characters, followed by forged log messages that may mislead administrators reviewing log output. | |
| References |
|
Status: PUBLISHED
Assigner: jenkins
Published: 2025-09-17T13:17:48.559Z
Updated: 2025-09-25T18:37:37.848Z
Reserved: 2025-09-16T16:16:05.526Z
Link: CVE-2025-59476
Updated: 2025-09-25T18:36:56.351Z
Status : Analyzed
Published: 2025-09-17T14:15:41.297
Modified: 2025-10-02T18:44:35.940
Link: CVE-2025-59476