The host is installed with Jenkins LTS through 2.138.1 or Jenkins rolling release through 2.145 and is prone to a session fixation vulnerability. A flaw is present in the application, which fails to properly handle an issue in core/src/main/java/hudson/security/HudsonPrivateSecurityRealm.java. Successful exploitation could allow attackers to obtain sensitive information.