#VU21176 Information disclosure in Jira Software - CVE-2019-8449
Published: September 18, 2019 / Updated: June 17, 2021
Jira Software
Atlassian
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to an information expose in the "/rest/api/latest/groupuserpicker" resource. A remote attacker can enumerate usernames and gain unauthorized access to sensitive information on the system.