Description
CRLF injection vulnerability in the CLI command documentation in Jenkins before 1.650 and LTS before 1.642.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
Remediation
References
http://rhn.redhat.com/errata/RHSA-2016-1773.html
https://access.redhat.com/errata/RHSA-2016:0711
https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2016-02-24
Related Vulnerabilities
CVE-2016-2510 Vulnerability in maven package org.beanshell:bsh
CVE-2021-31597 Vulnerability in npm package xmlhttprequest-ssl
CVE-2023-3696 Vulnerability in maven package org.webjars.npm:mongoose
CVE-2015-8859 Vulnerability in npm package send
CVE-2023-46131 Vulnerability in maven package org.grails:grails-encoder