The following flaw was found in Jenkins:
The /queue/api URL could return information about items not accessible to the current user (such as parameter names and values, build names, project descriptions, ...).
Low privileged users can gain some limited information about items they should not have access to.
External References:
https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2015-11-11