漏洞描述
Jira before 8.4.0 is susceptible to information disclosure. The /rest/api/latest/groupuserpicker resource can allow an attacker to enumerate usernames, and thereby potentially obtain sensitive information, modify data, and/or execute unauthorized operations.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
www.doyler.nethttps://www.doyler.net/security-not-included/more-jira-enumeration↗jira.atlassian.comhttps://jira.atlassian.com/browse/JRASERVER-69796↗packetstormsecurity.comhttp://packetstormsecurity.com/files/156172/Jira-8.3.4-Information-Disclosure.html↗github.comhttps://github.com/SexyBeast233/SecBooks↗github.comhttps://github.com/StarCrossPortal/scalpel↗