Hi Team,
We have identified few observations during system VA scan,
1. AutoComplete Attribute Not Disabled for Password in Form Based Authentication:The Web server allows form based authentication without disabling the AutoComplete feature for the password field.Autocomplete should be turned off for any input that takes sensitive information such as credit card number, CVV2/CVC code, U.S. social security number , etc.
2. Web Server Uses Plain-Text Form Based Authentication : The Web server uses plain-text form based authentication. A web page exists on the target host which uses an HTML login form. This data is sent from the client to the server in plain-text.
Please let us know how to fix this.
We are using JIRA 5.2.11
Thanks,
Sujata
Hi Sujata,
The first response is to upgrade to the latest Jira. Your version reached End-of-Life (ie it's no longer supported by Atlassian) a few years ago, so any security vulnerabilities will go unmodified unless you upgrade your system.
If this is not possible, you may need to do some custom modifications to the Jira core files.
Online forums and learning are now in one easy-to-use experience.
By continuing, you accept the updated Community Terms of Use and acknowledge the Privacy Policy. Your public name, photo, and achievements may be publicly visible and available in search engines.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.