Modify Attachment Security Policy

お困りですか?

アトラシアン コミュニティをご利用ください。

コミュニティに質問

プラットフォームについて: Server および Data Center のみ。この記事は、Server および Data Center プラットフォームのアトラシアン製品にのみ適用されます。

Support for Server* products ended on February 15th 2024. If you are running a Server product, you can visit the Atlassian Server end of support announcement to review your migration options.

*Fisheye および Crucible は除く

目的

Modify the Attachment Security Policy to control how attachments are handled within Jira, by either forcing the download of an attachment or displaying it inline.

ソリューション

The attachment settings can be modified within the Jira configuration.

  1. Navigate to 'Jira Administration -> System'.
  2. Select the 'Edit Settings' button near the top right corner.
  3. Locate the option 'Internet Explorer MIME Sniffing Security Hole Workaround Policy'.
Available Options
  • Insecure: inline display of attachments
  • Secure: forced download of attachments for all browsers
  • Work around Internet Explorer security hole


Attachment viewing security options for cross-site site scripting vulnerabilities present in Internet Explorer 7 and earlier. Use the workaround to reduce the risk of attacks to IE users via attachments. Use download-only mode to sacrifice attachment viewing convenience in all browsers and gain ultimate protection against hostile attachments. See JIRA Security Advisory 2008-08-26


説明 Modify the Attachment Security Policy
製品Jira
最終更新日: 2020 年 12 月 31 日

この内容はお役に立ちましたか?

はい
いいえ
この記事についてのフィードバックを送信する
Powered by Confluence and Scroll Viewport.