Record summary

CVE-2019-3401 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.

Description

The ManageFilters.jspa resource in Jira before version 7.13.3 and from version 8.0.0 before version 8.1.1 allows remote attackers to enumerate usernames via an incorrect authorisation check.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE ListBefore 7.13.3affected
8.0.0affected
Before 8.1.1affected

Nuclei templates

1
ProjectDiscoveryMEDIUMAtlassian Jira <7.13.3/8.0.0-8.1.1 - Incorrect AuthorizationCVSS 5.3

Atlasssian Jira before version 7.13.3 and from version 8.0.0 before version 8.1.1 is susceptible to incorrect authorization. The ManageFilters.jspa resource allows a remote attacker to enumerate usernames via an incorrect authorization check, thus possibly obtaining sensitive information, modifying data, and/or executing unauthorized operations.

Impact

The vulnerability allows unauthorized users to access sensitive information or perform unauthorized actions.

Remediation

Ensure this permission is restricted to specific groups that require it via Administration > System > Global Permissions. Turning the feature off will not affect existing filters and dashboards. If you change this setting, you will still need to update the existing filters and dashboards if they have already been shared publicly. Since Jira 7.2.10, a dark feature to disable site-wide anonymous access was introduced.

WeaknessesCWE-863
AuthorsTechbrunchFR, milo2012
Template tagscvecve2019jiraatlassianexposurevuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CPE: cpe:2.3:a:atlassian:jira:*:*:*:*:*:*:*:*
Shodan: http.component:"Atlassian Jira"
Shodan: http.component:"atlassian jira"
Shodan: http.component:"atlassian confluence"
Shodan: cpe:"cpe:2.3:a:atlassian:jira"

Source: ProjectDiscovery

References

2