Vulnerability record · CVE-2020-36289 · published 12 May 2021
CVE-2020-36289: Atlassian Jira Server and Data Center user enumeration via QueryComponentRendererValue
Atlassian · Data Center
Jira Server and Data Center expose the QueryComponentRendererValue!Default.jspa endpoint in a way that lets an unauthenticated user enumerate valid accounts, caused by incorrect authorization (CWE-863). The flaw affects versions before 8.5.13, 8.6.0 through 8.13.5, and 8.14.0 through 8.15.1. It matters because a reliable list of valid usernames is a prerequisite for password spraying and targeted phishing against Jira accounts.
Description
Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Information Disclosure vulnerability in the QueryComponentRendererValue!Default.jspa endpoint. The affected versions are before version 8.5.13, from version 8.6.0 before 8.13.5, and from version 8.14.0 before 8.15.1.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Automated analysis
high priorityThe flaw is trivially reachable without authentication and has a very high EPSS score, though it only discloses usernames and no KEV or public exploit is recorded.
What it is
Jira Server and Data Center expose the QueryComponentRendererValue!Default.jspa endpoint in a way that lets an unauthenticated user enumerate valid accounts, caused by incorrect authorization (CWE-863). The flaw affects versions before 8.5.13, 8.6.0 through 8.13.5, and 8.14.0 through 8.15.1. It matters because a reliable list of valid usernames is a prerequisite for password spraying and targeted phishing against Jira accounts.
Impact
An attacker gains a verified list of valid Jira usernames without credentials. That list enables credential-stuffing, password-spraying and social-engineering campaigns against the affected instance.
Attack surface
Reached over the network through the QueryComponentRendererValue!Default.jspa endpoint; the CVSS vector shows PR:N and UI:N, so no authentication and no user interaction are required.
Exploitation
Not listed in CISA KEV and no public exploit or ransomware use is recorded in the references, but EPSS is very high at 0.99209 (99.9th percentile), indicating strong predicted exploitation activity.
What to do
- Upgrade Jira Server and Data Center to 8.5.13, 8.13.5, 8.15.1 or later as applicable to your branch.
- If immediate patching is not possible, restrict network access to the Jira web interface to trusted users and networks.
- Enable and tune rate limiting or a WAF rule on the QueryComponentRendererValue!Default.jspa endpoint to slow enumeration.
- Review Jira account naming so usernames are not easily guessable, and enforce strong authentication such as SSO or MFA.
- Monitor authentication logs for spraying patterns against the enumerated accounts.
Detection
- Alert on repeated requests to QueryComponentRendererValue!Default.jspa from a single source or with varying query parameters.
- Baseline normal access to that endpoint and flag first-time or high-volume callers, especially unauthenticated ones.
- Correlate enumeration bursts with subsequent failed login attempts or password-spray patterns in Jira authentication logs.
- Watch for scanning tools or user-agent strings hitting Jira endpoints at unusual rates.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://jira.atlassian.com/browse/JRASERVER-71559 | Issue TrackingPermissions RequiredVendor Advisory |
| https://jira.atlassian.com/browse/JRASERVER-71559 | Issue TrackingPermissions RequiredVendor Advisory |
Track CVE-2020-36289 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-36289), CISA KEV, FIRST EPSS (scores of 2026-09-22). This page is refreshed as NVD updates the record.