S4E just found a high top 10 tcp port service scan
medium·Product Based Web Vulnerabilities·Updated Jan 8, 2024

CVE-2019-8446 Scanner

CVE-2019-8446 scanner - User Enumeration vulnerability in Atlassian Jira

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.4k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2019-8446
5.3
CVSS

The /rest/issueNav/1/issueTable resource in Jira before version 8.3.2 allows remote attackers to enumerate usernames via an incorrect authorisation check.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Jiraby Atlassian
AFFECTED< 8.3.2SAFE ✓≥ 8.3.2
Updated Aug 21, 2026View on NVD →
Detail

Jira is a popular project management tool developed by Atlassian. It is primarily used by software development teams to plan, track, and manage their work. Jira allows users to create, organize, and prioritize tasks, assign them to team members, and track progress through various stages of development. It is used by thousands of companies worldwide, including large enterprises like NASA, Uber, and Spotify.

However, the tool is not immune to security vulnerabilities. One such vulnerability is CVE-2019-8446 which was detected in Jira before version 8.3.2. This vulnerability allows remote attackers to enumerate usernames via an incorrect authorization check. It occurs when the user does not have the required permission to view the list of issues in the issue navigator, but Jira provides a partial response, revealing the usernames of Jira users.

This vulnerability could lead to potential security breaches if exploited by attackers. With the usernames, attackers can easily launch phishing attacks on unsuspecting users by gaining access to their accounts and stealing sensitive data. Furthermore, attackers can use the usernames to launch brute-force attacks on user passwords.

In conclusion, security vulnerabilities in digital assets are becoming increasingly common and it is essential to take precautions to protect them. s4e.io offers pro features that provide a comprehensive vulnerability assessment report, automated scans, and 24/7 support. By using this platform, organizations can quickly and easily identify vulnerabilities in their digital assets and take appropriate measures to address them.

 

REFERENCES

Solution Advice

To protect against this vulnerability, users can take the following precautions:

  • Update to the latest version of Jira, which includes a fix for this vulnerability.
  • Restrict access to the Jira instance by limiting user privileges.
  • Enable two-factor authentication to prevent unauthorized access to user accounts.
  • Implement network segmentation to isolate Jira from other critical systems.
  • Educate users on how to recognize and prevent phishing attacks.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.