Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Jira Info Disclosure Vulnerability in a verbose error page -

arthur.ly May 5, 2020

During our security scan, we detected a version for Apache Tomcat in a verbose error page.. is there a configuration that can be modified to omit web application info - or disable verbose error pages from loading?

1 answer

0 votes
Matt Doar
Community Champion
May 5, 2020

There are some features such as SAML in Jira Data Center that by default don't show exceptions in error pages unless configured to do so. But in general most Jira features show the exception to the user, though it may be hidden behind a "click for more info" link.

So in general I don't think there is a way to hide that kind of info at the moment.

Suggest an answer

Log in or Sign up to answer