The /rest/issueNav/1/issueTable resource in Jira before version 8.3.2 allows remote attackers to enumerate usernames via an incorrect authorisation check.
https://github.com/CyberTrashPanda/CVE-2019-8446
https://www.talosintelligence.com/vulnerability_reports/TALOS-2019-0839