Hi
We've got a security audit on our confluence installation and we are told that we have to disable the stacktrace information on the error pages.
I cannot find any information about that, is there a possibilitiy?
BR
Thomas
Thanks for answer.
Unfortunately I didn't find any solution for this issue in the OWASP documents or in the Tomcat documentation directly.
Does anyone have another idea?
cheers
Thomas
I am having the problem right now, trying to secure a Confluence-Installation after a Penetration Test. Did you by any Chance find a solution to disable Stack Traces?
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Confluence and JIRA are both run on tomcat. Looking around i could not find anything about this on Atlassian pages, but apache tomcat does have a few pages about it. Check out this: https://www.owasp.org/index.php/Securing_tomcat
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Online forums and learning are now in one easy-to-use experience.
By continuing, you accept the updated Community Terms of Use and acknowledge the Privacy Policy. Your public name, photo, and achievements may be publicly visible and available in search engines.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.