Hi
We've got a security audit on our confluence installation and we are told that we have to disable the stacktrace information on the error pages.
I cannot find any information about that, is there a possibilitiy?
BR
Thomas
Thanks for answer.
Unfortunately I didn't find any solution for this issue in the OWASP documents or in the Tomcat documentation directly.
Does anyone have another idea?
cheers
Thomas
I am having the problem right now, trying to secure a Confluence-Installation after a Penetration Test. Did you by any Chance find a solution to disable Stack Traces?
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Confluence and JIRA are both run on tomcat. Looking around i could not find anything about this on Atlassian pages, but apache tomcat does have a few pages about it. Check out this: https://www.owasp.org/index.php/Securing_tomcat
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Join us to learn how your team can stay fully engaged in meetings without worrying about writing everything down. Dive into Loom's newest feature, Loom AI for meetings, which automatically takes notes and tracks action items.
Register today!Online forums and learning are now in one easy-to-use experience.
By continuing, you accept the updated Community Terms of Use and acknowledge the Privacy Policy. Your public name, photo, and achievements may be publicly visible and available in search engines.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.