-
Type:
Suggestion
-
Resolution: Unresolved
-
None
-
Component/s: Security
-
8
Problem
The X-XSS-Protection header introduced in JRASERVER-25145 cannot be disabled.
Suggested Solution
Introduce an option to disable the X-XSS-Protection header, similar to the existing com.atlassian.jira.clickjacking.protection.disabled system property which allows disabling the X-Frame-Options and Content-Security-Policy headers.
Why This Is Important
As described in the following articles, the X-XSS-Protection header is generally considered to be obsolete and deprecated in modern usage and can have security drawbacks which outweigh its benefits:
- https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/X-XSS-Protection
- https://cheatsheetseries.owasp.org/cheatsheets/HTTP_Headers_Cheat_Sheet.html#x-xss-protection
Workaround
No workaround is currently available.