Uploaded image for project: 'Jira Data Center'
  1. Jira Data Center
  2. JRASERVER-70987

About Jira page can be accessed anonymously

XMLWordPrintable

      Issue Summary

      "About Jira" page can be accessed anonymously. This can expose the Jira application versions. Some customers might want to prevent this information from being available as it could be used to target other vulnerabilities specific to the version.

      Steps to Reproduce

      Access <JIRA BASE URL>/secure/AboutPage.jspa anonymously

      Expected Results

      The user gets redirected to log in

      Actual Results

      The page is shown:

      Notes
      This happens even if the public access is blocked using a flag in the dark features

      Workaround

      Create a block the URL from being accessed from the proxy side. Another option is doing it from Apache Tomcat: How to block access to a specific URL at Tomcat

              9e3a0496a19c Jakub Sildatk
              rchiquete Rene C. [Atlassian Support]
              Votes:
              32 Vote for this issue
              Watchers:
              38 Start watching this issue

                Created:
                Updated:
                Resolved: