REST API in Atlassian Jira Server and Jira Data Center before version 8.5.14, from version 8.6.0 before 8.13.6, and from version 8.14.0 before 8.16.1 allows remote attackers to enumerate usernames via a Sensitive Data Exposure vulnerability in the `/rest/api/latest/user/avatar/temporary` endpoint.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: atlassian

Published: 2021-07-20T03:25:12.678817Z

Updated: 2024-09-16T20:58:34.696Z

Reserved: 2021-01-25T00:00:00

Link: CVE-2021-26081

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2021-07-20T04:15:09.683

Modified: 2022-03-30T13:29:50.043

Link: CVE-2021-26081

cve-icon Redhat

No data.