CVE-2019-3403 on https://████/rest/api/2/user/picker?query=
Medium
U
U.S. Dept Of Defense
Submitted None
Actions:
Reported by
nagli
Vulnerability Details
Technical details and impact analysis
**Description:**
The endpoint at
```
https://████████/rest/api/2/user/picker?query=
```
Suffers from
CVE-2019-3403
Due to old version of jira.
{F125281}
## References
https://nvd.nist.gov/vuln/detail/CVE-2019-3403
~@naglinagli
## Impact
The /rest/api/2/user/picker rest resource in Jira before version 7.13.3, from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows remote attackers to enumerate usernames via an incorrect authorisation check.
## System Host(s)
███
## Affected Product(s) and Version(s)
## CVE Numbers
## Steps to Reproduce
Navigate to https://██████/rest/api/2/user/picker?query=admin
## Suggested Mitigation/Remediation Actions
Update the jira version
Related CVEs
Associated Common Vulnerabilities and Exposures
CVE-2019-3403
UNKNOWN
The /rest/api/2/user/picker rest resource in Jira before version 7.13.3, from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows remote attackers to enumerate usernames via an incorrect authorisation check.
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Information Disclosure