Jenkins through 2.218, LTS 2.204.1 and earlier, is susceptible to information disclosure. An attacker can access exposed session identifiers on a user detail object in the whoAmI diagnostic page and thus potentially access sensitive information, modify data, and/or execute unauthorized operations.
View the template here CVE-2020-2103.yaml
References:
https://www.jenkins.io/security/advisory/2020-01-29/#SECURITY-1695