Jenkins 2.218 and earlier, LTS 2.204.1 and earlier exposed session identifiers on a user's detail object in the whoAmI diagnostic page.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| org.jenkins-ci.main:jenkins-core(Maven) | 2.205 | 2.219 | N/A |
| org.jenkins-ci.main:jenkins-core(Maven) | 0 | 2.204.2 | N/A |
CVSS Metrics