CVE 5.3 MEDIUM

CVE-2025-59476_CVE-2025-59476

5.3 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Description

Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not restrict or transform the characters that can be inserted from user-specified content in log messages, allowing attackers able to control log message contents to insert line break characters, followed by forged log messages that may mislead administrators reviewing log output.

Basic Information

ID CVE-2025-59476
Source jenkins
Published Sep 17, 2025 at 13:17
Modified Sep 25, 2025 at 18:37

Affected Product

Vendor Jenkins Project
Product Jenkins
Version 2.516.3

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.