Atlasssian Jira before version 7.13.3 and from version 8.0.0 before version 8.1.1 is susceptible to incorrect authorization. The ManageFilters.jspa resource allows a remote attacker to enumerate usernames via an incorrect authorization check, thus possibly obtaining sensitive information, modifying data, and/or executing unauthorized operations.
id: CVE-2019-3401
info:
name: Atlassian Jira <7.13.3/8.0.0-8.1.1 - Incorrect Authorization
auth
...