Information disclosure on sim.starbucks.com
Team Summary
Official summary from Starbucks
johnstone discovered an outdated and publicly-exposed JIRA instance that was vulnerable to two known CVEs: • CVE-2019-3403: allowing an unauthenticated attacker to enumerate whether a user exists on the Jira or not • CVE-2019-8442: exposing pom.xml @johnstone — thank you for reporting this vulnerability and confirming the resolution.
Vulnerability Details
Technical details and impact analysis
Related CVEs
Associated Common Vulnerabilities and Exposures
The /rest/api/2/user/picker rest resource in Jira before version 7.13.3, from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows remote attackers to enumerate usernames via an incorrect authorisation check.
The CachingResourceDownloadRewriteRule class in Jira before version 7.13.4, and from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows remote attackers to access files in the Jira webroot under the META-INF directory via a lax path access check.
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Information Disclosure