Description
By accessing the endpoint /secure/popups/UserPickerBrowser.jspa?max=10, an unauthenticated attack can retrieve the Jira's users.
Remediation
Consider restricting unauthenticated access to this endpoint.
References
Related Vulnerabilities
phpMyAdmin Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2015-6830)
Adobe ColdFusion directory traversal
WordPress Plugin Cimy User Manager 'cimy_um_filename' Parameter Arbitrary File Disclosure (1.4.2)
Frontpage authors.pwd available
WordPress Plugin Contact Form Email Information Disclosure (1.2.66)