ASA-2019-00094 – Jenkins: Recursive token expansion results in information disclosure and DoS in Token Macro Plugin

This could be used by users able to affect input to token expansion (such as change log messages), to inject additional tokens into the input, which would then be expanded, resulting in information disclosure (for example values of environment variables), or denial of service.