### [CVE-2019-8449](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-8449) ![](https://img.shields.io/static/v1?label=Product&message=Jira&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=unspecified%20&color=brightgreen) ![](https://img.shields.io/static/v1?label=Vulnerability&message=Information%20Exposure&color=brightgreen) ### Description The /rest/api/latest/groupuserpicker resource in Jira before version 8.4.0 allows remote attackers to enumerate usernames via an information disclosure vulnerability. ### POC #### Reference - http://packetstormsecurity.com/files/156172/Jira-8.3.4-Information-Disclosure.html #### Github - https://github.com/0day404/vulnerability-poc - https://github.com/0ps/pocassistdb - https://github.com/0x48piraj/Jiraffe - https://github.com/0x48piraj/jiraffe - https://github.com/0xT11/CVE-POC - https://github.com/20142995/nuclei-templates - https://github.com/20142995/sectool - https://github.com/ARPSyndicate/cvemon - https://github.com/ARPSyndicate/kenzer-templates - https://github.com/ArrestX/--POC - https://github.com/Coldplay1517/Middleware-Vulnerability-detection-master - https://github.com/Elsfa7-110/kenzer-templates - https://github.com/Faizee-Asad/JIRA-Vulnerabilities - https://github.com/KayCHENvip/vulnerability-poc - https://github.com/LearnGolang/LearnGolang - https://github.com/Miraitowa70/POC-Notes - https://github.com/SexyBeast233/SecBooks - https://github.com/StarCrossPortal/scalpel - https://github.com/Threekiii/Awesome-POC - https://github.com/UGF0aWVudF9aZXJv/Atlassian-Jira-pentesting - https://github.com/XiaomingX/awesome-poc-for-red-team - https://github.com/anmolksachan/JIRAya - https://github.com/anonymous364872/Rapier_Tool - https://github.com/anquanscan/sec-tools - https://github.com/apachecn-archive/Middleware-Vulnerability-detection - https://github.com/apif-review/APIF_tool_2024 - https://github.com/apit-review-account/apit-tool - https://github.com/brunsu/woodswiki - https://github.com/d4n-sec/d4n-sec.github.io - https://github.com/developer3000S/PoC-in-GitHub - https://github.com/hackerhackrat/R-poc - https://github.com/hectorgie/PoC-in-GitHub - https://github.com/hktalent/bug-bounty - https://github.com/imhunterand/JiraCVE - https://github.com/jweny/pocassistdb - https://github.com/lovechinacoco/https-github.com-mai-lang-chai-Middleware-Vulnerability-detection - https://github.com/merlinepedra/nuclei-templates - https://github.com/merlinepedra25/nuclei-templates - https://github.com/mufeedvh/CVE-2019-8449 - https://github.com/pwnosec/jirapwn - https://github.com/r0eXpeR/redteam_vul - https://github.com/r0lh/CVE-2019-8449 - https://github.com/rezasarvani/JiraVulChecker - https://github.com/sevbandonmez/jira-scanner - https://github.com/sobinge/nuclei-templates - https://github.com/sushantdhopat/JIRA_testing - https://github.com/tdtc7/qps - https://github.com/und3sc0n0c1d0/UserEnumJira - https://github.com/woods-sega/woodswiki - https://github.com/youcans896768/APIV_Tool - https://github.com/zhoubingyan1/Golang-Learning