Information disclosure in Jira Software Server - CVE-2019-8449
Published: September 18, 2019 / Updated: June 17, 2021
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to an information expose in the "/rest/api/latest/groupuserpicker" resource. A remote attacker can enumerate usernames and gain unauthorized access to sensitive information on the system.
Affected software
How to mitigate CVE-2019-8449
Links to Public Exploits and PoC-codes
- Exploit #5791 - Jira 8.3.4 - Information Disclosure (Username Enumeration) (June 17, 2021)
- Exploit #5340 - UserEnumJira (Serie de scripts para enumerar nombres de usuarios de JIRA a partir de vulnerabilidades conocidas (CVE-2020-14181, CVE-2019-3403, CVE-2019-8449...)) (May 3, 2021)
- Exploit #265 - CVE-2019-8449 (CVE-2019-8449 Exploit for Jira v2.1 - v8.3.4) (March 18, 2020)
- Exploit #266 - CVE-2019-8449 (User Enumeration Proof Of Concept Exploit for CVE-2019-8449) (March 18, 2020)