mirror of
https://github.com/CVEProject/cvelist.git
synced 2025-07-29 05:56:59 +00:00
80 lines
2.9 KiB
JSON
80 lines
2.9 KiB
JSON
{
|
|
"CVE_data_meta": {
|
|
"ASSIGNER": "security@atlassian.com",
|
|
"DATE_PUBLIC": "2019-05-08T00:00:00",
|
|
"ID": "CVE-2019-3403",
|
|
"STATE": "PUBLIC"
|
|
},
|
|
"affects": {
|
|
"vendor": {
|
|
"vendor_data": [
|
|
{
|
|
"vendor_name": "Atlassian",
|
|
"product": {
|
|
"product_data": [
|
|
{
|
|
"product_name": "Jira",
|
|
"version": {
|
|
"version_data": [
|
|
{
|
|
"version_value": "7.13.3",
|
|
"version_affected": "<"
|
|
},
|
|
{
|
|
"version_value": "8.0.0",
|
|
"version_affected": ">="
|
|
},
|
|
{
|
|
"version_value": "8.0.4",
|
|
"version_affected": "<"
|
|
},
|
|
{
|
|
"version_value": "8.1.0",
|
|
"version_affected": ">="
|
|
},
|
|
{
|
|
"version_value": "8.1.1",
|
|
"version_affected": "<"
|
|
}
|
|
]
|
|
}
|
|
}
|
|
]
|
|
}
|
|
}
|
|
]
|
|
}
|
|
},
|
|
"data_format": "MITRE",
|
|
"data_type": "CVE",
|
|
"data_version": "4.0",
|
|
"description": {
|
|
"description_data": [
|
|
{
|
|
"lang": "eng",
|
|
"value": "The /rest/api/2/user/picker rest resource in Jira before version 7.13.3, from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows remote attackers to enumerate usernames via an incorrect authorisation check."
|
|
}
|
|
]
|
|
},
|
|
"problemtype": {
|
|
"problemtype_data": [
|
|
{
|
|
"description": [
|
|
{
|
|
"lang": "eng",
|
|
"value": "Incorrect Authorization (CWE-863)"
|
|
}
|
|
]
|
|
}
|
|
]
|
|
},
|
|
"references": {
|
|
"reference_data": [
|
|
{
|
|
"url": "https://jira.atlassian.com/browse/JRASERVER-69242",
|
|
"refsource": "MISC",
|
|
"name": "https://jira.atlassian.com/browse/JRASERVER-69242"
|
|
}
|
|
]
|
|
}
|
|
} |