{"id":7016,"date":"2025-09-18T10:03:43","date_gmt":"2025-09-18T10:03:43","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/09\/18\/jenkins-patches-multiple-vulnerabilities-that-allow-attackers-to-cause-a-denial-of-service\/"},"modified":"2025-09-18T10:03:43","modified_gmt":"2025-09-18T10:03:43","slug":"jenkins-patches-multiple-vulnerabilities-that-allow-attackers-to-cause-a-denial-of-service","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/09\/18\/jenkins-patches-multiple-vulnerabilities-that-allow-attackers-to-cause-a-denial-of-service\/","title":{"rendered":"Jenkins Patches Multiple Vulnerabilities that Allow Attackers to Cause a Denial of Service"},"content":{"rendered":"<p>    Jenkins Patches Multiple Vulnerabilities that Allow Attackers to Cause a Denial of Service<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Jenkins has released critical updates addressing four security flaws that unauthenticated and low-privileged attackers could exploit to disrupt service or glean sensitive configuration details.\u00a0<\/p>\n<p>Administrators running Jenkins weekly releases up to 2.527 or the Long-Term Support (LTS) stream up to 2.516.2 must upgrade to mitigate these risks.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-http-2-denial-of-service-cve-2025-5115\"><strong>HTTP\/2 Denial of Service (CVE-2025-5115)<\/strong><\/h2>\n<p>A high-severity issue (CVSS 3.1 A:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:N\/A:H) exists in the Winstone-Jetty HTTP\/2 implementation bundled with Jenkins core. When Jenkins is launched via an equivalent systemd service configuration, the outdated Jetty version is vulnerable to a <a href=\"https:\/\/cybersecuritynews.com\/denial-of-servicedos-attack\/\" target=\"_blank\" rel=\"noreferrer noopener\">denial of service<\/a> attack known as \u201cMadeYouReset.\u201d\u00a0<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"395\" height=\"32\" src=\"https:\/\/i0.wp.com\/cybersecuritynews.com\/wp-content\/uploads\/2025\/09\/image-105.png?resize=395%2C32&#038;ssl=1\" alt=\"Jenkins Patches Multiple Vulnerabilities\" class=\"wp-image-126734\" srcset=\"https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/09\/image-105.png 395w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/09\/image-105-300x24.png 300w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/09\/image-105-150x12.png 150w\" sizes=\"(max-width: 395px) 100vw, 395px\"><\/figure>\n<\/div>\n<p>Unauthenticated attackers can trigger unchecked <a href=\"https:\/\/cybersecuritynews.com\/http-2-madeyoureset-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">HTTP\/2<\/a> frames to exhaust server resources, causing Jenkins to crash.\u00a0<\/p>\n<p>This flaw affects Jenkins 2.523 and earlier, and LTS 2.516.2 and earlier when HTTP\/2 is enabled. HTTP\/2 remains disabled by default in native installers and official Docker images, reads the <a href=\"https:\/\/www.jenkins.io\/security\/advisory\/2025-09-17\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">advisory<\/a>.\u00a0<\/p>\n<p>The fixes in Jenkins 2.524 and LTS 2.516.3 update Jetty to version 12.0.25, removing the vulnerability. Administrators unable to upgrade immediately are strongly advised to disable HTTP\/2 support.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-permission-check-omissions-cve-2025-59474-cve-2025-59475\"><strong>Permission-Check Omissions (CVE-2025-59474, CVE-2025-59475)<\/strong><\/h2>\n<p>Two medium-severity flaws allow unauthorized enumeration of internal components. In the sidepanel executors widget, Jenkins 2.527 and earlier (LTS 2.516.2 and earlier) fail to enforce Overall\/Read permission, letting unauthenticated users list agent names (CVE-2025-59474).\u00a0<\/p>\n<p>Similarly, a bug in the authenticated user profile dropdown (CVE-2025-59475) permits attackers with minimal privileges to discover which plugins, such as the Credentials Plugin, are installed by inspecting menu entries.\u00a0<\/p>\n<p>Both issues are resolved in Jenkins weekly 2.528 and LTS 2.516.3, which remove the vulnerable sidepanel and enforce permission checks in profile menus.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-log-message-injection-cve-2025-59476\"><strong>Log Message Injection (CVE-2025-59476)<\/strong><\/h2>\n<p>Jenkins\u2019 console log formatter in versions up to 2.527 (LTS 2.516.2 and earlier) does not sanitize user-controlled content before writing to system logs (jenkins.log and equivalents).\u00a0<\/p>\n<p>Attackers can insert carriage return or line feed characters or even Unicode \u201cTrojan Source\u201d codepoints\u2014into log entries, forging misleading log lines that hamper incident response.\u00a0<\/p>\n<p>The update in weekly 2.528 and LTS 2.516.3 prefixes injected lines with indicators like [CR], [LF], or [CRLF] &gt;, but administrators are still advised to use log viewers that highlight unusual characters and restrict log access to trusted personnel.<\/p>\n<figure class=\"wp-block-table aligncenter\">\n<table class=\"has-fixed-layout\">\n<tbody>\n<tr>\n<td><strong>CVE<\/strong><\/td>\n<td><strong>Title<\/strong><\/td>\n<td><strong>CVSS 3.1 Score<\/strong><\/td>\n<td><strong>Severity<\/strong><\/td>\n<\/tr>\n<tr>\n<td>CVE-2025-5115<\/td>\n<td>HTTP\/2 denial of service in bundled Jetty<\/td>\n<td>7.5<\/td>\n<td>High<\/td>\n<\/tr>\n<tr>\n<td>CVE-2025-59474<\/td>\n<td>Missing permission check allows obtaining agent names<\/td>\n<td>5.3<\/td>\n<td>Medium<\/td>\n<\/tr>\n<tr>\n<td>CVE-2025-59475<\/td>\n<td>Missing permission check in authenticated users\u2019 profile menu<\/td>\n<td>4.6<\/td>\n<td>Medium<\/td>\n<\/tr>\n<tr>\n<td>CVE-2025-59476<\/td>\n<td>Log message injection vulnerability<\/td>\n<td>4.4<\/td>\n<td>Medium<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<h2 class=\"wp-block-heading\" id=\"h-mitigations\"><strong>Mitigations<\/strong><\/h2>\n<p>All Jenkins users should upgrade immediately: weekly releases to 2.528 and LTS to 2.516.3.\u00a0<\/p>\n<p>These versions collectively address the high-severity HTTP\/2 DoS (CVE-2025-5115) and the medium-severity permission-check and log injection flaws (CVE-2025-59474; CVE-2025-59475; CVE-2025-59476).\u00a0<\/p>\n<p>The security researchers Daniel Beck (CloudBees, Inc.), Manuel Fernandez (Stackhopper Security), and IBM Cloud Red Team members Robert Houtenbrink, Faris Mohammed, and Harsh Yadav reported these issues.\u00a0<\/p>\n<p>Administrators unable to upgrade should, at a minimum, disable HTTP\/2 and restrict access to log files to prevent exploitation.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 89%,rgb(169,184,195) 100%)\"><strong>Find this Story Interesting! Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener\">X<\/a>\u00a0to Get More Instant Updates<\/strong>.<\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/jenkins-patches-multiple-vulnerabilities\/\">Jenkins Patches Multiple Vulnerabilities that Allow Attackers to Cause a Denial of Service<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Florence Nightingale<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/jenkins-patches-multiple-vulnerabilities\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Jenkins Patches Multiple Vulnerabilities that Allow Attackers to Cause a Denial of Service Jenkins has released critical updates addressing four security flaws that unauthenticated and low-privileged attackers could exploit to disrupt service or glean sensitive configuration details.\u00a0 Administrators running Jenkins weekly releases up to 2.527 or the Long-Term Support (LTS) stream up to 2.516.2 must [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,131,648],"tags":[130],"class_list":["post-7016","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-vulnerability","category-vulnerability-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/7016"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=7016"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/7016\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=7016"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=7016"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=7016"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}