Jenkins through 2.196, LTS 2.176.3 and earlier prints the value of the cookie on the /whoAmI/ URL despite it being marked HttpOnly, thus making it possible to steal cookie-based authentication credentials if the URL is exposed or accessed via another cross-site scripting issue.
View the template here CVE-2019-10405.yaml
References:
https://nvd.nist.gov/vuln/detail/CVE-2019-10405