We have built one jira add on, need to run penetrating testing, was using OWASP ZAP tool to do that, but its blocking. Can please someone help me to do this.
Hello @vinay hegde ,
Welcome to the Atlassian Community!
If I understand correctly you have built a Connect Add-on for Jira Cloud and now you would like to test it for vulnerabilities using OWASP ZAP tool. Is this connect?
If this is correct then, even if I have never used OWSAP myself, from what I can read it is like having a proxy between the user browser and the web app. Therefore, I assume you need to be able to access your app from the browser in order to be able to run the vulnerability scan, but this is usually not something you can do with connect app.
Actually, what are you telling OWASP ZAP to connect to? What is returning access denied?
Also, for the future, please notice that this is not the best place to get help on development related questions.
The right resources are listed in https://developer.atlassian.com/resources.
Specifically:
Cheers,
Dario
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Not without more information :)
What exactly are you doing?
What are you seeing?
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
We built one jira add on, where you can add that add on to jira project from jira marketplace. I'm trying to run penetration testing on that add on using OWASP ZAP tool. Access is denied whenever I'm trying to run OWASP ZAP tool. How i can run penetrate testing on our add on?
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
So you're trying to test your jira add-on when its installed in a jira instance?
Assuming that you need to login to Jira then you need to configure ZAP to handle authentication.
There are several videos explaining ZAP authentication on https://www.zaproxy.org/zap-in-ten/
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.