Unrated severityNVD Advisory· Published Jul 20, 2021· Updated Oct 11, 2024
CVE-2021-26081
CVE-2021-26081
Description
REST API in Atlassian Jira Server and Jira Data Center before version 8.5.14, from version 8.6.0 before 8.13.6, and from version 8.14.0 before 8.16.1 allows remote attackers to enumerate usernames via a Sensitive Data Exposure vulnerability in the /rest/api/latest/user/avatar/temporary endpoint.
Affected products
2- Range: unspecified
- Range: unspecified
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- jira.atlassian.com/browse/JRASERVER-72499mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.