JIRASESSIONID values being discovered on crawling and are accessible via URL, why?

Milan Chheda [INFOSYSTA]
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
January 31, 2019

As a part of penetration testing, we crawled JIRA and as you can see in the below screenshot, JIRASESSIONID values are visible/discovered while crawling the JIRA website.

We would like to know why are they accessible? Are they valid? 

 

InkedjirasessionsIDs_LI.jpg

0 answers

Suggest an answer

Log in or Sign up to answer