The /rest/issueNav/1/issueTable resource in Jira before version 8.3.2 allows remote attackers to enumerate usernames via an incorrect authorisation check.
id: CVE-2019-8446
info:
name: Jira Improper Authorization
author: dhiyaneshDk
severity: mediu
...