5.3
CVE-2019-8448
- EPSS 0.37%
- Veröffentlicht 13.08.2019 15:15:12
- Zuletzt bearbeitet 21.11.2024 04:49:55
- Quelle security@atlassian.com
- CVE-Watchlists
- Unerledigt
The login.jsp resource in Jira before version 7.13.4, and from version 8.0.0 before version 8.2.2 allows remote attackers to enumerate usernames via an information disclosure vulnerability.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Atlassian ≫ Jira Server Version >= 7.11.0 < 7.13.4
Atlassian ≫ Jira Server Version >= 8.0.0 < 8.2.2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.37% | 0.58 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.3 | 3.9 | 1.4 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|