jira.atlassian.com
https://jira.atlassian.com/browse/JRASERVER-69777 CVE-2019-8446
MEDIUMNuclei
Atlassian Jira Server and Data Center Incorrect Authorization
Record summary
CVE-2019-8446 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.
Description
The /rest/issueNav/1/issueTable resource in Jira before version 8.3.2 allows remote attackers to enumerate usernames via an incorrect authorisation check.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jan 22, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
| CVE List | Before 8.3.2 | affected | |
Jira Server and Data CenterBrowse Atlassian / Jira Server and Data Center | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryMEDIUMJira Improper AuthorizationCVSS 5.3
The /rest/issueNav/1/issueTable resource in Jira before version 8.3.2 allows remote attackers to enumerate usernames via an incorrect authorisation check.
Impact
This vulnerability can lead to unauthorized access, data leakage, and potential compromise of the Jira application.
Remediation
Apply the latest security patches and updates provided by Atlassian to fix the vulnerability.
WeaknessesCWE-863
AuthorsdhiyaneshDk
Template tagscvecve2019jiraatlassianvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CPE: cpe:2.3:a:atlassian:jira_server:*:*:*:*:*:*:*:*
Shodan: http.component:"Atlassian Jira"
Shodan: http.component:"atlassian jira"
https://jira.atlassian.com/browse/JRASERVER-69777 https://www.talosintelligence.com/vulnerability_reports/TALOS-2019-0839 https://github.com/ARPSyndicate/kenzer-templates https://github.com/CyberTrashPanda/CVE-2019-8446 https://github.com/Elsfa7-110/kenzer-templates
Source: ProjectDiscovery
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-8446 talosintelligence.com
https://www.talosintelligence.com/vulnerability_reports/TALOS-2019-0839