Vulnerabilities
Vulnerable Software
Jenkins:  >> Jenkins  >> 2.516.2  Security Vulnerabilities
Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not perform a permission check for the authenticated user profile dropdown menu, allowing attackers without Overall/Read permission to obtain limited information about the Jenkins configuration by listing available options in this menu (e.g., whether Credentials Plugin is installed).
CVSS Score
4.3
EPSS Score
0.0
Published
2025-09-17
Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not restrict or transform the characters that can be inserted from user-specified content in log messages, allowing attackers able to control log message contents to insert line break characters, followed by forged log messages that may mislead administrators reviewing log output.
CVSS Score
5.3
EPSS Score
0.001
Published
2025-09-17


Contact Us

Shodan ® - All rights reserved