Our internal security audit has revealed that our confluence server is missing required security http headers:
HTTP 1.1 (non-HTTPS) - Required headers:
- Content-Security-Policy
- X-Content-Type-Options
- Cache-Control
How do we go about fixing this on our instance?
If we are required to update our version of Confluence to fix this, will this affect our existing Confluence data?