Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not restrict or transform the characters that can be inserted from user-specified content in log messages, allowing attackers able to control log message contents to insert line break characters, followed by forged log messages that may mislead administrators reviewing log output.
References
Link | Resource |
---|---|
https://www.jenkins.io/security/advisory/2025-09-17/#SECURITY-3424 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
02 Oct 2025, 18:44
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:jenkins:jenkins:*:*:*:*:lts:*:*:* cpe:2.3:a:jenkins:jenkins:*:*:*:*:-:*:*:* |
|
First Time |
Jenkins jenkins
Jenkins |
|
References | () https://www.jenkins.io/security/advisory/2025-09-17/#SECURITY-3424 - Vendor Advisory |
25 Sep 2025, 19:15
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.3 |
CWE | CWE-117 |
17 Sep 2025, 14:18
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-09-17 14:15
Updated : 2025-10-02 18:44
NVD link : CVE-2025-59476
Mitre link : CVE-2025-59476
CVE.ORG link : CVE-2025-59476
JSON object : View
Products Affected
jenkins
- jenkins
CWE
CWE-117
Improper Output Neutralization for Logs