Record summary

CVE-2019-8446 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.

Description

The /rest/issueNav/1/issueTable resource in Jira before version 8.3.2 allows remote attackers to enumerate usernames via an incorrect authorisation check.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jan 22, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

2
ProductSourceVersion rangeStatus
CVE ListBefore 8.3.2affected
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryMEDIUMJira Improper AuthorizationCVSS 5.3

The /rest/issueNav/1/issueTable resource in Jira before version 8.3.2 allows remote attackers to enumerate usernames via an incorrect authorisation check.

Impact

This vulnerability can lead to unauthorized access, data leakage, and potential compromise of the Jira application.

Remediation

Apply the latest security patches and updates provided by Atlassian to fix the vulnerability.

WeaknessesCWE-863
AuthorsdhiyaneshDk
Template tagscvecve2019jiraatlassianvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CPE: cpe:2.3:a:atlassian:jira_server:*:*:*:*:*:*:*:*
Shodan: http.component:"Atlassian Jira"
Shodan: http.component:"atlassian jira"

Source: ProjectDiscovery

References

3