← Back

CVE-2025-59476

nvd nist
Published: Sep 17, 2025Modified: Jun 17, 2026

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Exploitability: 3.9 / Impact: 1.4
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not restrict or transform the characters that can be inserted from user-specified content in log messages, allowing attackers able to control log message contents to insert line break characters, followed by forged log messages that may mislead administrators reviewing log output.

Affected (2)

Products: Jenkins: Jenkins
1 product
Jenkins
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Jenkins
Before 2.528
Before 2.516.3

References (2)

Source: jenkinsci-cert@googlegroups.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.