Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Our Jira site is potentially Vulnerable to Clickjacking , how to tackle that?

ronit.ghosh
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
November 1, 2020

Our Jira site is potentially Vulnerable to Clickjacking , how to tackle that?

Verison - 7.1.0 

What are the changes needs to be done , any help would be appreciated .

1 answer

1 accepted

2 votes
Answer accepted
Yevgen Lasman
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
November 1, 2020

Do you have an ability to upgrade it? The version you have has reached end of life and isn't supported by Atlassian, thus you won't get a fix for this version.

As for the clickjacking, this KB article seems to be relevant to your problem and includes the solution. Also, you may want to check JRASERVER-25143 which however is available in Jira 7.6.0 or newer.

ronit.ghosh
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
November 1, 2020

Thanks Yevgen , i may have to check on the upgrade part .

Meanwhile also how can we configure the remote web server to use HSTS ? 

Found  a link but wanted to check if this shall work or not - https://community.atlassian.com/t5/Jira-questions/Enabling-HTTP-Strict-Transport-Security-HSTS-for-Jira-8-4-3/qaq-p/1237404 

Suggest an answer

Log in or Sign up to answer