Need to run penetrating testing using OWASP ZAP tool on my jira add on.

vinay hegde November 21, 2020

We have built one jira add on, need to run penetrating testing, was using OWASP ZAP tool to do that, but its blocking. Can please someone help me to do this.

2 answers

1 accepted

0 votes
Answer accepted
Dario B
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
November 27, 2020

Hello @vinay hegde ,

Welcome to the Atlassian Community!

If I understand correctly you have built a Connect Add-on for Jira Cloud and now you would like to test it for vulnerabilities using OWASP ZAP tool. Is this connect? 

If this is correct then, even if I have never used OWSAP myself, from what I can read it is like having a proxy between the user browser and the web app. Therefore, I assume you need to be able to access your app from the browser in order to be able to run the vulnerability scan, but this is usually not something you can do with connect app.

Actually, what are you telling OWASP ZAP to connect to? What is returning access denied?

 

Also, for the future, please notice that this is not the best place to get help on development  related questions.

The right resources are listed in https://developer.atlassian.com/resources. 

Specifically:

 

Cheers,
Dario

vinay hegde November 29, 2020

Thank You Dario.

Like Dario B likes this
0 votes
SimonB
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
November 23, 2020

Not without more information :)

What exactly are you doing?

What are you seeing?

vinay hegde November 23, 2020

We built one jira add on, where you can add that add on to jira project from jira marketplace. I'm trying to run penetration testing on that add on using OWASP ZAP tool. Access is denied whenever I'm trying to run OWASP ZAP tool. How i can run penetrate testing on our add on? 

SimonB
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
November 27, 2020

So you're trying to test your jira add-on when its installed in a jira instance?

Assuming that you need to login to Jira then you need to configure ZAP to handle authentication.

There are several videos explaining ZAP authentication on https://www.zaproxy.org/zap-in-ten/

Like Dario B likes this

Suggest an answer

Log in or Sign up to answer
DEPLOYMENT TYPE
CLOUD
PRODUCT PLAN
FREE
PERMISSIONS LEVEL
Product Admin
TAGS
AUG Leaders

Atlassian Community Events