CVE-2019-8449
CVE-2019-8449
The /rest/api/latest/groupuserpicker resource in Jira before version 8.4.0 allows remote attackers to enumerate usernames via an information disclosure vulnerability.
Affected products
Atlassian · Jirapublic PoCs found — 4
githubgithub.com/mufeedvh/CVE-2019-8449★ 69githubgithub.com/r0lh/CVE-2019-8449★ 2cve_referencepacketstormsecurity.com/files/156172/Jira-8.3.4-Information-Disclosure.htmlunverifiedexploitdbwww.exploit-db.com/exploits/47990unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →