Description
Jenkins 2.218 and earlier, LTS 2.204.1 and earlier exposed session identifiers on a user's detail object in the whoAmI diagnostic page.
Remediation
References
Related Vulnerabilities
Liferay DXP Other Vulnerability (CVE-2023-33947)
Jenkins 7PK - Security Features Vulnerability (CVE-2014-9635)
WordPress Plugin AVH Extended Categories Widgets SQL Injection (4.0.0)
WordPress Plugin IMPress for IDX Broker Cross-Site Scripting (3.0.5)
WordPress Plugin YaySMTP-Simple WP SMTP Mail Information Disclosure (2.2)