Dear Team,
As we have deployed the License version for Confluence Application on Server premises
License ID - (SEN-20218955).
This is regards to found the bugs for VAPT scanning which we have deployed application on Windows server, hence we are looking out solutions as we found the bugs for confluence application.
Requesting you please have look and also assign some person which can contact us for further investigation and solutions.
Name | Risk Level | Number of Instances | Details | Remarks |
CSP: Wildcard Directive | Medium | 44 | Details are attached in VAPT Reports | |
Vulnerable JS Library | Medium | 19 | Details are attached in VAPT Reports | |
Absence of Anti-CSRF Tokens | Low | 38 | Details are attached in VAPT Reports | |
Cookie No HttpOnly Flag | Low | 23 | Details are attached in VAPT Reports | |
Cookie Without SameSite Attribute | Low | 25 | Details are attached in VAPT Reports | |
Private IP Disclosure | Low | 40 | Details are attached in VAPT Reports | |
X-Content-Type-Options Header Missing | Low | 86 | Details are attached in VAPT Reports | |
Information Disclosure - Sensitive Information in URL | Informational | 1 | Details are attached in VAPT Reports | |
Information Disclosure - Suspicious Comments | Informational | 118 | Details are attached in VAPT Reports | |
Timestamp Disclosure - Unix | Informational | 326 | Details are attached in VAPT Reports |
Please Note - There is no attachment options for VAPT Scanning details reports.
Many Thanks.
Raj Prajapati
Mob +91 9892668573
Hi Raj,
the prodecure as for security issues with Atlassian is as follows:
Cheers,
Daniel
Hi Daniel,
As per above issue we have also updated the above latest version but still VAPT scanning showing Vulnerability exist in the system.
Can i get valuable support to resolve that issue.
Thanks
Raj Prajapati
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
there is no support here - this is Community where users help users.
This topic seems to me being full of more specific questions which you could direct to Atlassian Support - if an upgrade did not help.
https://support.atlassian.com/contact
Regards,
Daniel
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Then how we can raise the bugs with Support Teams, as per security aspect thats are very major bugs which they have to resolve.
Please help us to raise the bugs to Support Teams.
Regards,
Raj
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
I pasted in a link in the answer above - you fill out a form and get a reply.
https://support.atlassian.com/contact
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
I have gone through given url but again raising ticket to community groups only.
Can you please show us the way to raise the ticket through confluence developer?
I will be appreciated for your help.
Regards,
Raj
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Online forums and learning are now in one easy-to-use experience.
By continuing, you accept the updated Community Terms of Use and acknowledge the Privacy Policy. Your public name, photo, and achievements may be publicly visible and available in search engines.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.