Vulnerability HTTP Security Header Not Detected

Sai Sreejith
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
October 29, 2017

I am getting the  6666 port vulnerability on Jira servers. 

Jira integrated with apache. 

QID is 11827 , Vulnerability title is  HTTP Security Header Not Detected,

 

Could you please help some one to help me here to resolve the issue

 

Regards

Sai 

 

1 answer

0 votes
Nic Brough -Adaptavist-
Community Leader
Community Leader
Community Leaders are connectors, ambassadors, and mentors. On the online community, they serve as thought leaders, product experts, and moderators.
October 29, 2017

This is an apache problem, not Jira. 

Check your apache configuration contains

Header always append X-Frame-Options SAMEORIGIN
Header set X-XSS-Protection "1; mode=block"
Header set X-Content-Type-Options nosniff
Sai Sreejith
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
October 30, 2017

I added the same in my Appache configuration and after scan again it is there with same error 

Suggest an answer

Log in or Sign up to answer