Hi,
Below is the vulnerability report we received.
Summary:
Affected versions of Atlassian Jira Server and Data Center allow remote, unauthenticated attackers to view custom field names and custom SLA names via an Information Disclosure vulnerability in the /secure/QueryComponent!Default.jspa endpoint.
Platform Affected: [website]
https://vzmdev.atlassian.net
Please provide steps to remediate this vulnerability
JIRA Version Used: 8.13