CVE-2025-59476
MEDIUMJenkins < 2.516.3 and < 2.528 - Log Forgery via Line Break Injection
Title source: llmDescription
Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not restrict or transform the characters that can be inserted from user-specified content in log messages, allowing attackers able to control log message contents to insert line break characters, followed by forged log messages that may mislead administrators reviewing log output.
References (2)
Core 2
Core References
Vendor Advisory vendor-advisory
https://www.jenkins.io/security/advisory/2025-09-17/#SECURITY-3424
Scores
CVSS v3
5.3
EPSS
0.0034
EPSS Percentile
25.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-117
Status
published
Products (3)
jenkins/jenkins
< 2.516.3
jenkins/jenkins
< 2.528
org.jenkins-ci.main/jenkins-core
0 - 2.516.3Maven
Published
Sep 17, 2025
Tracked Since
Feb 18, 2026