Relevant reference

patch-1
Noam Rathaus 2021-04-06 13:27:39 +03:00
parent ac932b6c33
commit 098d3157e5
1 changed files with 1 additions and 1 deletions

View File

@ -5,7 +5,7 @@ info:
author: Ganofins
severity: medium
description: The /rest/api/2/user/picker rest resource in Jira before version 7.13.3, from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows remote attackers to enumerate usernames via an incorrect authorisation check.
reference: https://nvd.nist.gov/vuln/detail/CVE-2019-3403
reference: https://jira.atlassian.com/browse/JRASERVER-69242
tags: cve,cve2019,atlassian,jira
requests: