• Icon: Suggestion Suggestion
    • Resolution: Timed out
    • None
    • Board configuration
    • None
    • 1
    • 2
    • We collect Jira feedback from various sources, and we evaluate what we've collected when planning our product roadmap. To understand how this piece of feedback will be reviewed, see our Implementation of New Features Policy.

      Our security department has scanned our Jira (v7.4.2#74004-sha1:586975d) using an IBM tool called Appscan.  It reported a possible vulnerability.  I have to prepare a response to indicate if this is a known problem and when or if it will be fixed.  I require your assistance please. Text from the report follows:

      1. Missing Secure Attribute in Encrypted Session (SSL) Cookie- It may be possible to steal user and session information (cookies) that was sent during an encrypted session.

       Recommendation:  Add the 'Secure' attribute to all sensitive cookies.

       

            [JSWSERVER-16436] Missing Secure Attribute in Encrypted Session (SSL) Cookie

            Katherine Yabut made changes -
            Workflow Original: JAC Suggestion Workflow [ 3065351 ] New: JAC Suggestion Workflow 3 [ 3657270 ]
            Status Original: RESOLVED [ 5 ] New: Closed [ 6 ]
            SET Analytics Bot made changes -
            Support reference count Original: 1 New: 2
            UIS New: 1
            David Black made changes -
            Resolution New: Timed out [ 10 ]
            Status Original: Gathering Interest [ 11772 ] New: Resolved [ 5 ]
            Owen made changes -
            Workflow Original: Confluence Workflow - Public Facing v4 [ 2631940 ] New: JAC Suggestion Workflow [ 3065351 ]
            SET Analytics Bot made changes -
            Support reference count New: 1
            steve moffat created issue -

              Unassigned Unassigned
              90e0b4a8fa9d steve moffat
              Votes:
              0 Vote for this issue
              Watchers:
              4 Start watching this issue

                Created:
                Updated:
                Resolved: