CVE-2016-0789: Jenkins
Medium severity, CVSS 6.1. EPSS: 1.8% chance of exploitation in the next 30 days.
CRLF injection vulnerability in the CLI command documentation in Jenkins before 1.650 and LTS before 1.642.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
Affected products
- Jenkins Jenkins: up to and including 1.642.1; up to and including 1.649
- Red Hat Openshift: version 3.1 only
Published 2016-04-07. Last modified 2026-06-17.