Description
Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Information Disclosure vulnerability in the QueryComponentRendererValue!Default.jspa endpoint. The affected versions are before version 8.5.13, from version 8.6.0 before 8.13.5, and from version 8.14.0 before 8.15.1.
Remediation
References
Related Vulnerabilities
Sqlite NULL Pointer Dereference Vulnerability (CVE-2019-19880)
IBM WebSEAL Use of a Broken or Risky Cryptographic Algorithm Vulnerability (CVE-2023-38371)
Oracle HTTP Server CVE-2020-2952 Vulnerability (CVE-2020-2952)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2014-0215)
WordPress Plugin Floating Social Bar Cross-Site Scripting (1.1.6)