Dear Team,
As we have deployed the License version for Confluence Application on Server premises
License ID - (SEN-20218955).
This is regards to found the bugs for VAPT scanning which we have deployed application on Windows server, hence we are looking out solutions as we found the bugs for confluence application.
Requesting you please have look and also assign some person which can contact us for further investigation and solutions.
| Name | Risk Level | Number of Instances | Details | Remarks |
| CSP: Wildcard Directive | Medium | 44 | Details are attached in VAPT Reports | |
| Vulnerable JS Library | Medium | 19 | Details are attached in VAPT Reports | |
| Absence of Anti-CSRF Tokens | Low | 38 | Details are attached in VAPT Reports | |
| Cookie No HttpOnly Flag | Low | 23 | Details are attached in VAPT Reports | |
| Cookie Without SameSite Attribute | Low | 25 | Details are attached in VAPT Reports | |
| Private IP Disclosure | Low | 40 | Details are attached in VAPT Reports | |
| X-Content-Type-Options Header Missing | Low | 86 | Details are attached in VAPT Reports | |
| Information Disclosure - Sensitive Information in URL | Informational | 1 | Details are attached in VAPT Reports | |
| Information Disclosure - Suspicious Comments | Informational | 118 | Details are attached in VAPT Reports | |
| Timestamp Disclosure - Unix | Informational | 326 | Details are attached in VAPT Reports | |
Please Note - There is no attachment options for VAPT Scanning details reports.
Many Thanks.
Raj Prajapati
Mob +91 9892668573