Description
Jenkins 2.218 and earlier, LTS 2.204.1 and earlier exposed session identifiers on a user's detail object in the whoAmI diagnostic page.
Remediation
References
Related Vulnerabilities
WordPress Plugin 404 to 301-Redirect, Log and Notify 404 Errors Cloaking (2.2.9)
Ruby on Rails Improper Input Validation Vulnerability (CVE-2019-5420)
ownCloud Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-5665)
WordPress Plugin All-In-One Security (AIOS)-Security and Firewall Cross-Site Request Forgery (5.1.0)
WordPress Plugin WebLibrarian Multiple Unspecified Vulnerabilities (2.6.3.1)