Jenkins through 2.218, LTS 2.204.1 and earlier, is susceptible to information disclosure. An attacker can access exposed session identifiers on a user detail object in the whoAmI diagnostic page and thus potentially access sensitive information, modify data, and/or execute unauthorized operations.
id: CVE-2020-2103
info:
name: Jenkins <=2.218 - Information Disclosure
author: c-sh0
severity
...