we have detected few vulnerability for existing JIRA version 8.5.5. most of them can be mitigated by upgrading the version however please confirm if the vulnerability commented below can be mitigated by upgrading the version.
Refer this List of vulnerabilities in Jira 8.5.5 With Solutions
All Vulnerabilities and solutions
Accept the answer if it helps
Hi,
The first should not be relevant if you've enforced https
For the second, autocomplete is not set to false on the password field by default in 8.20.6 - but you'll find that most sites have autocomplete enabled.
CCM
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.