CVE Vulnerabilities

CVE-2019-8448

Published: Aug 13, 2019 | Modified: Mar 25, 2022
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

The login.jsp resource in Jira before version 7.13.4, and from version 8.0.0 before version 8.2.2 allows remote attackers to enumerate usernames via an information disclosure vulnerability.

Affected Software

Name Vendor Start Version End Version
Jira_server Atlassian 7.11.0 (including) 7.13.4 (excluding)
Jira_server Atlassian 8.0.0 (including) 8.2.2 (excluding)

References