-
Type:
Suggestion
-
Resolution: Unresolved
-
Component/s: Incoming Email - Mail Handlers
-
None
-
2
-
1
Problem
Currently, when a malicious file is sent as an email attachment to a JSM Email Channel, the file is uploaded and attached to the ticket. Atlassian's malware scanning detects the file post-upload and displays a warning to users at download time, however, the file is still stored on the ticket.
Suggested Solution
Provide an option to block malicious files at the point of upload, preventing them from being attached to the ticket in the first place when received via the JSM Email Channel. This would add a proactive security layer rather than relying solely on post-upload detection.
Why This Is Important
Customers using JSM Email Channels exposed to external senders (e.g. shared inboxes, support addresses) have no native control to prevent malicious files from entering their Jira environment. Current mitigation requires configuring email gateway-level security externally.
Workaround
(Add a workaround, if available)