CVE-2019-3403: Medium severity atlassian jira vulnerability
The /rest/api/2/user/picker rest resource in Jira before version 7.13.3, from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows remote attackers to enumerate usernames via an incorrect authorisation check.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-3403?
CVE-2019-3403 is considered a high severity vulnerability due to its potential for allowing remote attackers to enumerate usernames.
How do I fix CVE-2019-3403?
To fix CVE-2019-3403, upgrade Jira to version 7.13.3 or to versions 8.0.4 and above, and to 8.1.1 or later.
What types of attacks are possible with CVE-2019-3403?
CVE-2019-3403 enables attackers to perform user enumeration attacks which can lead to further exploitation.
Is my version of Jira affected by CVE-2019-3403?
If you are using any version of Jira prior to 7.13.3, or between 8.0.0 and 8.0.4 or between 8.1.0 and 8.1.1, then your version is affected by CVE-2019-3403.
What are the implications of CVE-2019-3403 on user privacy?
CVE-2019-3403 can lead to unauthorized disclosure of usernames, which may compromise user privacy and security within the affected Jira environments.