Jenkins Log Message Injection Vulnerability

Vulnerability

A log message injection vulnerability exists in Jenkins versions 2.527 and earlier, as well as LTS 2.516.2 and earlier. The issue arises because the log formatter does not properly restrict or transform user-specified content in log messages. This flaw allows attackers to insert line break characters followed by deceptive log messages, potentially misleading administrators who are reviewing the log output.

Impact

Exploitation of this vulnerability could lead to the injection of misleading log messages, causing confusion for administrators monitoring log activities.

Remediation

Users of Jenkins weekly should update to version 2.528, and users of Jenkins LTS should update to version 2.516.3. These versions include the necessary fix for this vulnerability.

Added: Sep 17, 2025, 2:18 PM
Updated: Sep 17, 2025, 2:26 PM

Vulnerability Rating

Custom Algorithm
spread
5.7
impact
0.6
exploitability
7.0
remediation
7.7
relevance
0.5
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.