🔙 목록으로 돌아가기

CVE-2019-3401: Atlassian Jira <7.13.3/8.0.0-8.1.1 - Incorrect Authorization

TitleAtlassian Jira <7.13.3/8.0.0-8.1.1 - Incorrect Authorization
AuthorTechbrunchFR,milo2012
SeverityMedium
ImpactThe vulnerability allows unauthorized users to access sensitive information or perform unauthorized actions.
RemediationEnsure this permission is restricted to specific groups that require it via Administration > System > Global Permissions. Turning the feature off will not affect existing filters and dashboards. If you change this setting, you will still need to update the existing filters and dashboards if they have already been shared publicly. Since Jira 7.2.10, a dark feature to disable site-wide anonymous access was introduced.
CVSS Score5.3
EPSS Score0.64371
CVE IDCVE-2019-3401
CWE IDCWE-863
Shodan Queryhttp.component:"Atlassian Jira"http.component:"atlassian jira"http.component:"atlassian confluence"cpe:"cpe:2.3:a:atlassian:jira"
Tags cve cve2019 jira atlassian exposure vuln

🔍 Vulnerability Description

Atlasssian Jira before version 7.13.3 and from version 8.0.0 before version 8.1.1 is susceptible to incorrect authorization. The ManageFilters.jspa resource allows a remote attacker to enumerate usernames via an incorrect authorization check, thus possibly obtaining sensitive information, modifying data, and/or executing unauthorized operations.

🌐 HTTP Request

GET /secure/ManageFilters.jspa?filter=popular&filterView=popular HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2019/CVE-2019-3401.yaml

🦈 Packet Capture: ⬇️ Download cve-2019-3401.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A