An improper authorization vulnerability exists in Jenkins Subversion Plugin version 2.10.2 and earlier in SubversionStatus.java and SubversionRepositoryStatus.java that allows an attacker with network access to obtain a list of nodes and users.
https://github.com/advisories/GHSA-w9gq-8q35-3jcc
https://jenkins.io/security/advisory/2018-02-26/#SECURITY-724