Showing results for 
Search instead for 
Did you mean: 
Sign up Log in

It's not the same without you

Join the community to find out what other Atlassian users are discussing, debating and creating.

Atlassian Community Hero Image Collage

Strict-Transport-Security header

All of our atlassian products are showing a vulnerability due to incorrectly configured Strict-Transport-Security header on the web servers.  I've found fixes for jira, and I'm assuming confluence.    But fisheye seems to be a different setting,  is there any way to adjust header without doing some kind of reverse proxy?

1 answer

0 votes
Daniel Eads Atlassian Team Aug 18, 2020

Hi Steve,

While a reverse proxy would be my first choice, you might have success modifying the config.xml file. Fisheye uses Jetty for its application server (vs Tomcat for Jira and Confluence), so the setup is different than other documentation you might use for other products.

Here's some discussion around adding the stsMaxAge value into a config.xml file for Jetty:

Note that this is untested on my end. Using a reverse proxy is typically how I'd recommend terminating SSL with Fisheye.


Suggest an answer

Log in or Sign up to answer
Community showcase
Published in Jira Service Management

Security Advisory for Jira Service Management

On October 20, 2021, Atlassian published a security advisory for Jira Service Management. The full advisory is available at this link.  We've seen a number of questions already asking for...

63 views 0 1
Read article

Community Events

Connect with like-minded Atlassian users at free events near you!

Find an event

Connect with like-minded Atlassian users at free events near you!

Unfortunately there are no Community Events near you at the moment.

Host an event

You're one step closer to meeting fellow Atlassian users at your local event. Learn more about Community Events

Events near you