CVE-2025-59476

Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not restrict or transform the characters that can be inserted from user-specified content in log messages, allowing attackers able to control log message contents to insert line break characters, followed by forged log messages that may mislead administrators reviewing log output.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:jenkins:jenkins:*:*:*:*:lts:*:*:*
cpe:2.3:a:jenkins:jenkins:*:*:*:*:-:*:*:*

History

04 Nov 2025, 22:16

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2025/09/17/1 -

Information

Published : 2025-09-17 14:15

Updated : 2025-11-04 22:16


NVD link : CVE-2025-59476

Mitre link : CVE-2025-59476

CVE.ORG link : CVE-2025-59476


JSON object : View

Products Affected

jenkins

  • jenkins
CWE
CWE-117

Improper Output Neutralization for Logs