Description
The login.jsp resource in Jira before version 7.13.4, and from version 8.0.0 before version 8.2.2 allows remote attackers to enumerate usernames via an information disclosure vulnerability.
Remediation
References
Related Vulnerabilities
Ruby Permissions, Privileges, and Access Controls Vulnerability (CVE-2011-1005)
XWiki Missing Authorization Vulnerability (CVE-2022-23617)
WordPress Plugin Migration, Backup, Staging-WPvivid Security Bypass (0.9.35)
WordPress Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-6634)