vendor:
Jira
by:
Mohammed Aloraimi
N/A
CVSS
Information Disclosure
N/A
CWE
Product Name: Jira
Affected Version From: 8.11.x
Affected Version To: 8.15.0
Patch Exists: N/A
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Kali Linux
2021
Atlassian Jira 8.15.0 – Information Disclosure (Username Enumeration)
A username information disclosure vulnerability exists in Atlassian JIRA from versions 8.11.x to 8.15.x. Unauthenticated users can ENUMRATE valid users via /secure/QueryComponent!Jql.jspa endpoint.
Mitigation:
N/A