I was evaluating Jira Service Managment last week. Along the way, some Jira product installed a cookie on my browser without my permission. The cookie is "ajs_anonymous_id".
The cookie begins and ends with the %22 character, which triggers some firewalls (Sophos UTM) to think this is a SQL Injection attack.
The end result is I spent all weekend troubleshooting why my browser (Brave) was unable to access ANY of our internal systems, and was getting locked out of resources for possible SQL Injection attacks.
Question: is anyone familiar with this cookie and is the source Jira? I'm seeing conflicting evidence on this.
OK, I confirmed that this is coming from Jira.
I deleted the help-desk widgets from all my web sites, and I had to manually go and delete the Jira cookies from browsers. Systems are back up now.
Atlassian: you are using illegal and unconventional characters in your cookie. You are breaking applications.
First, why are you putting %22 at the beginning and ending of the cookie value?
Second, WHY is there such a cookie AT ALL? This appears to be an attempt to track people who do not want to be tracked. Am I wrong?
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.