Information Disclosure via QueryCompenentRenderer API
Reference:
No Reference
Title:
Information Disclosure via QueryCompenentRenderer API
Overview:
Affected versions of Atlassian Jira Server and Data Centre allowed an unauthenticated remote attacker to fetch IssueProject and Sprint information via Information Disclosure Vulnerability via /secure/QueryComponentRendererValueDefault.jspa endpoint.