As a part of penetration testing, we crawled JIRA and as you can see in the below screenshot, JIRASESSIONID values are visible/discovered while crawling the JIRA website.
We would like to know why are they accessible? Are they valid?
It looks like you're new here. Sign in or register to get started.