漏洞描述
The /rest/issueNav/1/issueTable resource in Jira before version 8.3.2 allows remote attackers to enumerate usernames via an incorrect authorisation check.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
jira.atlassian.comhttps://jira.atlassian.com/browse/JRASERVER-69777↗www.talosintelligence.comhttps://www.talosintelligence.com/vulnerability_reports/TALOS-2019-0839↗github.comhttps://github.com/ARPSyndicate/kenzer-templates↗github.comhttps://github.com/CyberTrashPanda/CVE-2019-8446↗github.comhttps://github.com/Elsfa7-110/kenzer-templates↗