vendor:
Jira
by:
Mufeed VH
5.3
CVSS
MEDIUM
Information Disclosure
20
CWE
Product Name: Jira
Affected Version From: 2.1
Affected Version To: 8.3.4
Patch Exists: YES
Related CWE: CVE-2019-8449
CPE: a:atlassian:jira
Other Scripts:
N/A
Platforms Tested: Pop!_OS 19.10
2019
Jira 8.3.4 – Information Disclosure (Username Enumeration)
A vulnerability in Jira versions 2.1 to 8.3.4 allows an attacker to enumerate usernames by sending a specially crafted request to the Jira REST API. This vulnerability is due to insufficient input validation of the query parameter in the Jira REST API. An attacker can leverage this vulnerability to enumerate usernames and gain access to the Jira instance.
Mitigation:
Upgrade to Jira version 8.3.5 or later.