After enabling Jelly support, we have decided to run a security scan on our JIRA instance with Acunetix Enterprise web scanner. I would like if anyone has done it before would share your experience and toughts on that.
Even though our major concern is Jelly support, we are keen to study other vulnerabilities as well. One such reported by Acunetix was, source code disclosure in the Dashboard jspa.
I would like to know what kind of scan setup should I use, and are there any known false positives?
Thanks in advance!