Atlassian Jira Server and Data Center before 8.5.8 and 8.6.0 through 8.11.1 are susceptible to information disclosure via the /secure/QueryComponent!Default.jspa endpoint. An attacker can view custom field names and custom SLA names.
View the template here CVE-2020-14179.yaml
References:
https://github.com/hackerhackrat/R-poc