You're on your way to the next level! Join the Kudos program to earn points and save your progress.
Level 1: Seed
25 / 150 points
Next: Root
1 badge earned
Challenges come and go, but your rewards stay with you. Do more to earn more!
What goes around comes around! Share the love by gifting kudos to your peers.
Keep earning points to reach the top of the leaderboard. It resets every quarter so you always have a chance!
Join now to unlock these features and more
The Atlassian Community can help you and your team get more value out of Atlassian products and practices.
We're looking at mitigating the recent security issue found with Atlassian products and a MITM attack. Suggestion from CloudSek say to administratively limit the amount of time a cookie can last, but if I just wanted to administratively wipe all cookies, as a precaution, is there a way to do this from any of the Software Apps?
@Matt Ray Welcome to the Atlassian community
There is nothing in the Atlassian applications that would allow you to force the clearing of browser cookies associated with the application after a specific period.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You might want to skim through https://community.atlassian.com/t5/Trust-Security-articles/Atlassian-response-to-claims-regarding-session-tokens-cookies/ba-p/2217925 as well.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Yes, I read this earlier today. We heard of the vulnerability on the 14th and did all our research based on CloudTek's article. Because the article you sent wasn't released until yesterday, we didn't have it when we were digging for information on the 14th, but it is comforting to know it is not the issue we thought it was. Thanks, @Nic Brough -Adaptavist-
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Well, just because Atlassian says it's not as big of a problem as CloudTek says it is, doesn't mean that's completely true. They seem to be trying to minimize the issue on the link you gave me above. When in reality, if someone can get your session key, they can change your password and access your data. That's why Atlassian is telling you to RESET your passwords, not change them. The vulnerability is still there. If I get your session key/cookie it's good for 30 days unless someone resets the password.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
True, but be aware that CloudTek are aggressively marketing their tools, and this "report" looks very much like a way to advertise without appearing to be blatantly selling.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.