CVE-2019-8449
62Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 85%
from disclosure to weapon144 days
Published on NVDSep 11
1st PoC+144d
exploitation probability
85%top 1% of all CVEs
observed exploitation
nono source reports it
4 public exploit(s)
The /rest/api/latest/groupuserpicker resource in Jira before version 8.4.0 allows remote attackers to enumerate usernames via an information disclosure vulnerability.
Affected products
Atlassian · Jirapublic PoCs found — 4
exploitdbwww.exploit-db.com/exploits/47990unverifiedgithubgithub.com/mufeedvh/CVE-2019-8449★ 69githubgithub.com/r0lh/CVE-2019-8449★ 2cve_referencepacketstormsecurity.com/files/156172/Jira-8.3.4-Information-Disclosure.htmlunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.