CVE-2017-1000401: Jenkins
Low severity, CVSS 2.2. EPSS: 0.4% chance of exploitation in the next 30 days.
The Jenkins 2.73.1 and earlier, 2.83 and earlier default form control for passwords and other secrets, <f:password/>, supports form validation (e.g. for API keys). The form validation AJAX requests were sent via GET, which could result in secrets being logged to a HTTP access log in non-default configurations of Jenkins, and made available to users with access to these log files. Form validation for <f:password/> is now always sent via POST, which is typically not logged.
Affected products
- Jenkins Jenkins: up to and including 2.73.1; up to and including 2.83
Published 2018-01-26. Last modified 2026-06-17.