Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-59476


Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not restrict or transform the characters that can be inserted from user-specified content in log messages, allowing attackers able to control log message contents to insert line break characters, followed by forged log messages that may mislead administrators reviewing log output.


Published

2025-09-17T14:15:41.297

Last Modified

2025-10-02T18:44:35.940

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 5.3 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-117

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application jenkins jenkins < 2.516.3 Yes
Application jenkins jenkins < 2.528 Yes

References