Description
Jenkins 2.218 and earlier, LTS 2.204.1 and earlier exposed session identifiers on a user's detail object in the whoAmI diagnostic page.
Remediation
References
Related Vulnerabilities
Resin Application Server Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-2969)
Apache HTTP Server Improper Input Validation Vulnerability (CVE-2011-4317)
OpenSSL Integer Overflow or Wraparound Vulnerability (CVE-2016-2177)
WordPress Plugin SlideDeck 2 Lite Responsive Content Slider Local/Remote File Inclusion (2.3.3)