Hello, I am working with our security team on a vulnerability report for my Jira Software local instance. The tool, IBM App Scan, reports many cross-site request forgery vulnerabilities. However, it is likely that the majority, if not all, are false positives. Given that I don't want to go through each one individually to prove that they are false positives to our security (normal procedure here), I was wondering if there was a document or website link that I could point them to about Jira's built in XSRF protection?
I am using Jira Software 7.10.0.
Thanks!
Byron Douglas