The login.jsp resource in Jira before version 7.13.4, and from version 8.0.0 before version 8.2.2 allows remote attackers to enumerate usernames via an information disclosure vulnerability.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://jira.atlassian.com/browse/JRASERVER-69797 |
History
No history.
MITRE
Status: PUBLISHED
Assigner: atlassian
Published: 2019-08-13T14:39:56.841578Z
Updated: 2024-09-16T22:20:34.740Z
Reserved: 2019-02-18T00:00:00
Link: CVE-2019-8448
Vulnrichment
No data.
NVD
Status : Modified
Published: 2019-08-13T15:15:12.027
Modified: 2024-11-21T04:49:55.393
Link: CVE-2019-8448
Redhat
No data.