Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-1000401

Опубликовано: 11 окт. 2017
Источник: redhat
CVSS3: 2.2
EPSS Низкий

Описание

The Jenkins 2.73.1 and earlier, 2.83 and earlier default form control for passwords and other secrets, <f:password/>, supports form validation (e.g. for API keys). The form validation AJAX requests were sent via GET, which could result in secrets being logged to a HTTP access log in non-default configurations of Jenkins, and made available to users with access to these log files. Form validation for <f:password/> is now always sent via POST, which is typically not logged.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Enterprise 3jenkinsAffected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-532
https://bugzilla.redhat.com/show_bug.cgi?id=1501819jenkins: Form validation for password fields was sent via GET (SECURITY-616)

EPSS

Процентиль: 11%
0.00039
Низкий

2.2 Low

CVSS3

Связанные уязвимости

CVSS3: 2.2
ubuntu
около 8 лет назад

The Jenkins 2.73.1 and earlier, 2.83 and earlier default form control for passwords and other secrets, <f:password/>, supports form validation (e.g. for API keys). The form validation AJAX requests were sent via GET, which could result in secrets being logged to a HTTP access log in non-default configurations of Jenkins, and made available to users with access to these log files. Form validation for <f:password/> is now always sent via POST, which is typically not logged.

CVSS3: 2.2
nvd
около 8 лет назад

The Jenkins 2.73.1 and earlier, 2.83 and earlier default form control for passwords and other secrets, <f:password/>, supports form validation (e.g. for API keys). The form validation AJAX requests were sent via GET, which could result in secrets being logged to a HTTP access log in non-default configurations of Jenkins, and made available to users with access to these log files. Form validation for <f:password/> is now always sent via POST, which is typically not logged.

CVSS3: 2.2
debian
около 8 лет назад

The Jenkins 2.73.1 and earlier, 2.83 and earlier default form control ...

CVSS3: 2.2
github
больше 3 лет назад

Improper Input Validation in Jenkins

EPSS

Процентиль: 11%
0.00039
Низкий

2.2 Low

CVSS3