-
Bug
-
Resolution: Unresolved
-
Low
-
None
-
5.1.2
-
5.01
-
12
-
Severity 3 - Minor
-
0
-
Symptoms
Since 5.1.2, JIRA specifies "X-Content-Type-Options: nosniff" in the headers of all pages. This means that IE will not display any image which was uploaded with the incorrect MIME type. It's hard to reproduce this issue when uploading new images as they are automatically converted to PNG, however any images uploaded in previous versions before this was done are affected. It may also be possible to get such images into JIRA by specifying the wrong MIME type in a REST API request.
Steps to Reproduce
- Find any image file in JIRA which has the wrong MIME type
- Try to view it in IE
Workaround
Re-upload the image so that it gets converted to PNG.
- is related to
-
JRASERVER-31885 Uppercase Image File Extensions Cause Broken Images in IE due to nosniff Header
-
- Closed
-
-
CONFSERVER-26848 Confluence allows images to be uploaded with the wrong mime type, which causes them to not display in IE due to nosniff
-
- Closed
-
- relates to
-
JRASERVER-30717 JIRA 5.2 is currently listing the mime-type for 'swf' as 'application/x-shockwave-flash2-preview'
-
- Closed
-
-
JRASERVER-62233 Image unable to load when attaching JPEG image with Ctrl + V in IE11
-
- Gathering Impact
-