Description
The login.jsp resource in Jira before version 7.13.4, and from version 8.0.0 before version 8.2.2 allows remote attackers to enumerate usernames via an information disclosure vulnerability.
Remediation
References
Related Vulnerabilities
WordPress Plugin Resume Submissions & Job Postings Arbitrary File Upload (2.5.3)
Magento Improper Authorization Vulnerability (CVE-2020-24405)
WebLogic CVE-2023-21956 Vulnerability (CVE-2023-21956)
GlassFish CVE-2018-2911 Vulnerability (CVE-2018-2911)
Joomla! Core 3.x.x Cross-Site Request Forgery (3.2.0 - 3.4.1)