-
Public Security Vulnerability
-
Resolution: Fixed
-
Low (View bug fix roadmap)
-
8.16.1, 8.5.17, 8.13.9, 8.18.1
-
None
-
5.3
-
Medium
-
CVE-2021-39118
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to discover the usernames and full names of users via an enumeration vulnerability in the /rest/api/1.0/render endpoint.
The affected versions are before version 8.19.0.
*Affected versions:*
- version < 8.19.0
*Fixed versions:*
- 8.19.0
[JRASERVER-72736] User Enumeration via /rest/api/1.0/render endpoint - CVE-2021-39118
Remote Link | New: This issue links to "Page (Confluence)" [ 733450 ] |
Remote Link | New: This issue links to "Page (Confluence)" [ 589130 ] |
CVE ID | New: CVE-2021-39118 |
Security | Original: Atlassian Staff [ 10750 ] |
Resolution | New: Fixed [ 1 ] | |
Status | Original: Draft [ 12872 ] | New: Published [ 12873 ] |
Labels | Original: advisory advisory-to-release dont-import security | New: CVE-2021-39118 advisory advisory-to-release dont-import security |
Summary | Original: User Enumeration via /rest/api/1.0/render endpoint - CVE-in progress | New: User Enumeration via /rest/api/1.0/render endpoint - CVE-2021-39118 |
Remote Link | New: This issue links to "Page (Confluence)" [ 576733 ] |
I'd like to test my project against this vulnerability, is there a proof of concept?