We have built one jira add on, need to run penetrating testing, was using OWASP ZAP tool to do that, but its blocking. Can please someone help me to do this.
Hello @vinay hegde ,
Welcome to the Atlassian Community!
If I understand correctly you have built a Connect Add-on for Jira Cloud and now you would like to test it for vulnerabilities using OWASP ZAP tool. Is this connect?
If this is correct then, even if I have never used OWSAP myself, from what I can read it is like having a proxy between the user browser and the web app. Therefore, I assume you need to be able to access your app from the browser in order to be able to run the vulnerability scan, but this is usually not something you can do with connect app.
Actually, what are you telling OWASP ZAP to connect to? What is returning access denied?
Also, for the future, please notice that this is not the best place to get help on development related questions.
The right resources are listed in https://developer.atlassian.com/resources.
Specifically:
Cheers,Dario
Not without more information
What exactly are you doing?
What are you seeing?
We built one jira add on, where you can add that add on to jira project from jira marketplace. I'm trying to run penetration testing on that add on using OWASP ZAP tool. Access is denied whenever I'm trying to run OWASP ZAP tool. How i can run penetrate testing on our add on?
So you're trying to test your jira add-on when its installed in a jira instance?
Assuming that you need to login to Jira then you need to configure ZAP to handle authentication.
There are several videos explaining ZAP authentication on https://www.zaproxy.org/zap-in-ten/
Thank You Dario.
It looks like you're new here. Sign in or register to get started.