CVE-2019-3403
MEDIUM 5.3EPSS 52.6%
The /rest/api/2/user/picker rest resource in Jira before version 7.13.3, from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows remote attackers to enumerate usernames via an incorrect authorisation check.
- CVSS v3.1
- 5.3 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N - CVSS v2.0
- 5.0 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N - EPSS
- 52.64% chance of exploitation in the next 30 days, 99th percentile
- Nuclei
- medium · CWE-863
- Published
- 2019-05-22
- Updated
- 2024-09-17
Proof-of-concept exploits (1)
- davidmckennirey/CVE-2019-34032★ · 2021-03-22