Description
By accessing the endpoint /secure/popups/UserPickerBrowser.jspa?max=10, an unauthenticated attack can retrieve the Jira's users.
Remediation
Consider restricting unauthenticated access to this endpoint.
References
Related Vulnerabilities
WebLogic Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-10334)
WordPress Plugin U BuddyPress Forum Attachment 'fileurl' Parameter Remote File Disclosure (1.1.1)
Unrestricted access to NGINX+ Dashboard
WordPress Plugin Stop User Enumeration User Enumeration (1.2.4)