CVE-2019-8446: Medium severity atlassian server vulnerability
Published Aug 23, 2019
·Updated
The /rest/issueNav/1/issueTable resource in Jira before version 8.3.2 allows remote attackers to enumerate usernames via an incorrect authorisation check.
Affected Software
1 affected component
Atlassian Jira Server>=7.6<8.3.2
Event History
Aug 23, 2019
CVE Published
via MITRE·01:49 PM
Data Sourced
via MITRE·01:49 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-8446?
CVE-2019-8446 is considered a medium severity vulnerability due to its potential for username enumeration.
2
How do I fix CVE-2019-8446?
To fix CVE-2019-8446, upgrade to Jira Server version 8.3.2 or later.
3
Who is affected by CVE-2019-8446?
CVE-2019-8446 affects all Jira Server versions from 7.6 up to, but not including, 8.3.2.
4
What type of attack does CVE-2019-8446 enable?
CVE-2019-8446 enables remote attackers to enumerate usernames through an authentication bypass.
5
Is CVE-2019-8446 a local or remote vulnerability?
CVE-2019-8446 is a remote vulnerability, allowing attackers to exploit it from a remote location.