Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

JIRA 5.2.11 system vulnerabilities

Sujata June 13, 2018

Hi Team,

  We have identified few observations during  system VA scan,

 

1. AutoComplete Attribute Not Disabled for Password in Form Based Authentication:The Web server allows form based authentication without disabling the AutoComplete feature for the password field.Autocomplete should be turned off for any input that takes sensitive information such as credit card number, CVV2/CVC code, U.S. social security number , etc.

2. Web Server Uses Plain-Text Form Based Authentication : The Web server uses plain-text form based authentication. A web page exists on the target host which uses an HTML login form.  This data is sent from the client to the server in plain-text.

 Please let us know how to fix this.

 We are using JIRA 5.2.11

 

Thanks,

Sujata

1 answer

1 accepted

1 vote
Answer accepted
Sana Safai
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
June 13, 2018

Hi Sujata,

The first response is to upgrade to the latest Jira. Your version reached End-of-Life (ie it's no longer supported by Atlassian) a few years ago, so any security vulnerabilities will go unmodified unless you upgrade your system.

If this is not possible, you may need to do some custom modifications to the Jira core files.

Sujata June 14, 2018

Thanks.

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events