vendor:
JIRA
by:
Dolev Farhi
5.3
CVSS
MEDIUM
User Enumeration
200
CWE
Product Name: JIRA
Affected Version From: < 7.13.16, 8.0.0
Affected Version To: < 8.5.7, 8.6.0
Patch Exists: YES
Related CWE: CVE-2020-14181
CPE: a:atlassian:jira
Other Scripts:
N/A
Platforms Tested: None
2020
Atlassian JIRA 8.11.1 – User Enumeration
This vulnerability allows an attacker to enumerate valid usernames on Atlassian JIRA versions < 7.13.16, 8.0.0 ≤ version < 8.5.7, 8.6.0 ≤ version < 8.12.0. An attacker can send a GET request to the ViewUserHover.jspa endpoint with a valid username and if the response does not contain the string 'User does not exist', then the username is valid. This vulnerability was discovered by Dolev Farhi and was assigned CVE-2020-14181.
Mitigation:
Upgrade to the latest version of Atlassian JIRA. Additionally, ensure that the ViewUserHover.jspa endpoint is not publicly accessible.