Our Jira site is potentially Vulnerable to Clickjacking , how to tackle that?
Verison - 7.1.0
What are the changes needs to be done , any help would be appreciated .
Do you have an ability to upgrade it? The version you have has reached end of life and isn't supported by Atlassian, thus you won't get a fix for this version.
As for the clickjacking, this KB article seems to be relevant to your problem and includes the solution. Also, you may want to check JRASERVER-25143 which however is available in Jira 7.6.0 or newer.
Thanks Yevgen , i may have to check on the upgrade part .
Meanwhile also how can we configure the remote web server to use HSTS ?
Found a link but wanted to check if this shall work or not - https://community.atlassian.com/t5/Jira-questions/Enabling-HTTP-Strict-Transport-Security-HSTS-for-Jira-8-4-3/qaq-p/1237404
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.