Description
An information disclosure vulnerability in Jira allows an unauthenticated user to enumerate users via /ViewUserHover.jspa endpoint.
Remediation
Upgrade to the latest version of Jira
References
Related Vulnerabilities
SAP weak/predictable user credentials
WordPress username enumeration
WordPress Plugin Acumbamail Information Disclosure (1.0.4)
PrestaShop Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2020-15080)
PHP Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2018-15132)