PT-2019-16560 · Atlassian · Jira

Publicado

2019-05-22

·

Atualizado

2022-03-25

·

CVE-2019-3403

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Jira versions prior to 7.13.3 Jira versions 8.0.0 through 8.0.3 Jira versions 8.1.0
Description The issue concerns an incorrect authorization check in the "/rest/api/2/user/picker" API endpoint, allowing remote attackers to enumerate usernames.
Recommendations For versions prior to 7.13.3, update to version 7.13.3 or later. For versions 8.0.0 through 8.0.3, update to version 8.0.4 or later. For version 8.1.0, update to version 8.1.1 or later.

Correção

Incorrect Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-3403

Produtos afetados

Jira