PoC Index

CVE-2019-3403

MEDIUM 5.3EPSS 52.6%

The /rest/api/2/user/picker rest resource in Jira before version 7.13.3, from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows remote attackers to enumerate usernames via an incorrect authorisation check.

CVSS v3.1
5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS v2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS
52.64% chance of exploitation in the next 30 days, 99th percentile
Nuclei
medium · CWE-863
Published
2019-05-22
Updated
2024-09-17

Proof-of-concept exploits (1)

Nuclei templates (1)

References

Related