Confluence 7.19.6 on Windows Server 2019 Standard and Tomcat 9.0.65
Hi. Hope someone can advise with this please? Our penetration test threw up a few things that need to be addressed. One thing is MULTIPLE MISSING HTTP SECURITY HEADERS
I have found that these can be added to, or already exist in the web.xml. Now I am confused about which web.xml is being used by Confluence. There is the web.xml in Atlassian\Conf and another one in Atlassian\Confluence\confluence\WEB-INF
I was of the opinion that it is using the web.xml in WEB-INF but that does not contain anything related to httpHeaderSecurity whereas the one in conf does. In the conf web.xml they are all commented out. The WEB-INF web.xml contains references to Confluence whereas the conf/web.xml appears to be entirely generic
Perhaps both are in play in some form or another? Which file should I be adding my HTTP Headers to in order to tighten up my web application security please?
Since I have Confluence connected to JIRA and am using JIRA Directory Server I also need to be careful that I don't unwittingly break my access between the two applications
Any assistance or advice gratefully received. TIA