we have detected few vulnerability for existing JIRA version 8.5.5. most of them can be mitigated by upgrading the version however please confirm if the vulnerability commented below can be mitigated by upgrading the version.
Refer this List of vulnerabilities in Jira 8.5.5 With Solutions
All Vulnerabilities and solutions
Accept the answer if it helps
Hi,
The first should not be relevant if you've enforced https
For the second, autocomplete is not set to false on the password field by default in 8.20.6 - but you'll find that most sites have autocomplete enabled.
CCM
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Online forums and learning are now in one easy-to-use experience.
By continuing, you accept the updated Community Terms of Use and acknowledge the Privacy Policy. Your public name, photo, and achievements may be publicly visible and available in search engines.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.