Jenkins
cpe:2.3:a:jenkins:jenkins:*:*:*:*:*:*:*
- <= 2.527
- <= 2.516.2
A log message injection vulnerability exists in Jenkins versions 2.527 and earlier, as well as LTS 2.516.2 and earlier. The issue arises because the log formatter does not properly restrict or transform user-specified content in log messages. This flaw allows attackers to insert line break characters followed by deceptive log messages, potentially misleading administrators who are reviewing the log output.
Exploitation of this vulnerability could lead to the injection of misleading log messages, causing confusion for administrators monitoring log activities.
Users of Jenkins weekly should update to version 2.528, and users of Jenkins LTS should update to version 2.516.3. These versions include the necessary fix for this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.