CVE-2019-8448

MEDIUM

Jira Server 7.11.0-7.13.3 and 8.0.0-8.2.1 - Username Enumeration via Login Page

Title source: llm
STIX 2.1

Description

The login.jsp resource in Jira before version 7.13.4, and from version 8.0.0 before version 8.2.2 allows remote attackers to enumerate usernames via an information disclosure vulnerability.

References (1)

Core 1
Core References
Vendor Advisory x_refsource_misc
https://jira.atlassian.com/browse/JRASERVER-69797

Scores

CVSS v3 5.3
EPSS 0.0022
EPSS Percentile 44.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

Status published
Products (1)
atlassian/jira_server 7.11.0 - 7.13.4
Published Aug 13, 2019
Tracked Since Feb 18, 2026