• Icon: Suggestion Suggestion
    • Resolution: Timed out
    • None
    • Board configuration
    • None
    • 1
    • 2
    • We collect Jira feedback from various sources, and we evaluate what we've collected when planning our product roadmap. To understand how this piece of feedback will be reviewed, see our Implementation of New Features Policy.

      Our security department has scanned our Jira (v7.4.2#74004-sha1:586975d) using an IBM tool called Appscan.  It reported a possible vulnerability.  I have to prepare a response to indicate if this is a known problem and when or if it will be fixed.  I require your assistance please. Text from the report follows:

      1. Missing Secure Attribute in Encrypted Session (SSL) Cookie- It may be possible to steal user and session information (cookies) that was sent during an encrypted session.

       Recommendation:  Add the 'Secure' attribute to all sensitive cookies.

       

          Form Name

            [JSWSERVER-16436] Missing Secure Attribute in Encrypted Session (SSL) Cookie

            David Black added a comment - Information on configuring Jira with TLS can be found at https://confluence.atlassian.com/adminjiraserver/running-jira-applications-over-ssl-or-https-938847764.html .

            Found this in the forums... I need to add secure="true" in our server.xml, and re-test  I think this will solve the issue.
                secure="true"
                proxyName="jira.example.com"
                proxyPort="443"
                scheme="https"

            steve moffat added a comment - Found this in the forums... I need to add secure="true" in our server.xml, and re-test  I think this will solve the issue.     secure="true"     proxyName="jira.example.com"     proxyPort="443"     scheme="https"

              Unassigned Unassigned
              90e0b4a8fa9d steve moffat
              Votes:
              0 Vote for this issue
              Watchers:
              4 Start watching this issue

                Created:
                Updated:
                Resolved: