Description
The /rest/api/latest/groupuserpicker resource in Jira before version 8.4.0 allows remote attackers to enumerate usernames via an information disclosure vulnerability.
Remediation
References
Related Vulnerabilities
MySQL CVE-2022-21607 Vulnerability (CVE-2022-21607)
WordPress Plugin WordLift-AI powered SEO-Schema Cross-Site Scripting (3.37.1)
OpenVPN AS Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2014-9104)
WordPress Plugin WordPress Button Plugin MaxButtons Security Bypass (1.19.0)
Liferay Portal Missing Authorization Vulnerability (CVE-2022-39975)