Information Disclosure via QueryCompenentRenderer API
Affected versions of Atlassian Jira Server and Data Centre allowed an unauthenticated remote attacker to fetch IssueProject and Sprint information via Information Disclosure Vulnerability via /secure/QueryComponentRendererValueDefault.jspa endpoint.