id: CVE-2019-3401 info: name: Atlassian JIRA Information Exposure (CVE-2019-3401) author: TechbrunchFR,milo2012 severity: medium description: The ManageFilters.jspa resource in Jira before version 7.13.3 and from version 8.0.0 before version 8.1.1 allows remote attackers to enumerate usernames via an incorrect authorisation check. reference: - https://jira.atlassian.com/browse/JRASERVER-69244 classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N cvss-score: 5.3 cve-id: CVE-2019-3401 cwe-id: CWE-863 tags: cve,cve2019,jira,atlassian,exposure requests: - method: GET path: - "{{BaseURL}}/secure/ManageFilters.jspa?filter=popular&filterView=popular" matchers: - type: word words: - '' - 'Manage Filters - Jira' condition: and # Remediation: # Ensure that this permission is restricted to specific groups that require it. # You can restrict it in Administration > System > Global Permissions. # Turning the feature off will not affect existing filters and dashboards. # If you change this setting, you will still need to update the existing filters and dashboards if they have already been # shared publicly. # Since Jira 7.2.10, a dark feature to disable site-wide anonymous access was introduced.