First published: Wed May 22 2019(Updated: )
The ManageFilters.jspa resource in Jira before version 7.13.3 and from version 8.0.0 before version 8.1.1 allows remote attackers to enumerate usernames via an incorrect authorisation check.
Credit: security@atlassian.com
Affected Software | Affected Version | How to fix |
---|---|---|
Atlassian Jira | <7.13.3 | |
Atlassian Server | >=8.0.0<8.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-3401 has been rated as a medium severity vulnerability due to its potential for information disclosure.
To mitigate CVE-2019-3401, upgrade Jira to version 7.13.3 or version 8.1.1 and above.
CVE-2019-3401 allows remote attackers to enumerate usernames, which can lead to targeted attacks against those users.
If you are using Jira versions prior to 7.13.3 or between 8.0.0 and 8.1.1, your installation is vulnerable to CVE-2019-3401.
CVE-2019-3401 is an authorization issue that enables attackers to access unauthorized user information.