-
Suggestion
-
Resolution: Low Engagement
-
None
-
None
Our security office pointed out to me today that email notifications from our Jira instance include the version number in the email. This also brought up that Jira exposes this to the public through the webapp as well. This is highly insecure and is a basic security precaution for any web application. Never expose the version of your software to the public. The only way I have found to hide these is to edit velocity template files, which will then be reverted next time I upgrade Jira.
This is another security feature that needs to be addressed. Combine this with the insecure version of JQuery that Jira runs and this application is starting to feel insecure to us.
Form Name |
---|
Hi,
Thank you for raising and watching this suggestion. We regret to inform you that due to limited demand, we have no plans to implement it in the foreseeable future. In order to set expectations, we're closing this request.
This is an automated update triggered by low engagement with this suggestion (number of votes, number of watchers).
We hope you will appreciate our candid communication and our attempts to become more transparent about our priorities. You can read more about our approach to highly voted suggestions here, and how we prioritise what to implement here.
To learn more about our recent investments in Jira Service Management and Data Center, please check our public roadmap and our two dashboards containing recently resolved issues, and current work and future plans.
Regards,
Charlie
Jira Service Management, Server & Data Center