CVE-2019-3401
Atlassian Jira <7.13.3/8.0.0-8.1.1 - Incorrect Authorization
Record summary
CVE-2019-3401 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.
Description
The ManageFilters.jspa resource in Jira before version 7.13.3 and from version 8.0.0 before version 8.1.1 allows remote attackers to enumerate usernames via an incorrect authorisation check.
Exploitation context
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
| CVE List | Before 7.13.3 | affected | |
| 8.0.0 | affected | ||
| Before 8.1.1 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMAtlassian Jira <7.13.3/8.0.0-8.1.1 - Incorrect AuthorizationCVSS 5.3
Atlasssian Jira before version 7.13.3 and from version 8.0.0 before version 8.1.1 is susceptible to incorrect authorization. The ManageFilters.jspa resource allows a remote attacker to enumerate usernames via an incorrect authorization check, thus possibly obtaining sensitive information, modifying data, and/or executing unauthorized operations.
Impact
The vulnerability allows unauthorized users to access sensitive information or perform unauthorized actions.
Remediation
Ensure this permission is restricted to specific groups that require it via Administration > System > Global Permissions. Turning the feature off will not affect existing filters and dashboards. If you change this setting, you will still need to update the existing filters and dashboards if they have already been shared publicly. Since Jira 7.2.10, a dark feature to disable site-wide anonymous access was introduced.
Source: ProjectDiscovery