Type:
Enhancement
Status:
Closed
Priority:
Medium
Resolution:
Unresolved
Module:
BenAdmin
- Security
Item State:
Production Complete
- Closed
Vulnerability Description
Transport Layer Security (TLS) version 1.0 has been found to contain protocol-level weaknesses.
Impact
Given the theoretical nature of attacks on TLS 1.0, supporting TLS 1.0 is not a risk-oriented decision. That being said, history has shown that as cryptographic attacks age, they get stronger (i.e. easier to exploit).
Verification and Attack Information
Praetorian verified the TLS v1.0 protocol was enabled on the application server using SSLScan, an automated SSL/TLS scanning tool. The application server accepted the TLS v1.0 protocol, as shown in the images below.
Recommendation
Praetorian recommends following Mozilla’s SSL/TLS (see reference below) configuration suggestions as a guide for ciphersuite support. These configurations provide high-security and high-availability to SSL/TLS clients.
References
https://mozilla.github.io/server-side-tls/ssl-config-generator/
https://cipherli.st/
https://www.wolfssl.com/wolfSSL/Blog/Entries/2010/12/14_A_Comparison_of_TLS_1.1_and_TLS_1.2.html
Vijayendra Shinde (Inactive)
made changes -
20/Sep/16 06:24 AM
Item State
Parent values: Production Complete(10222)Level 1 values: Closed(10223)
{"report":{"apdex":1,"isInitial":true,"journeyId":"11287bf8-42e2-4e10-a99c-9ba1cdf12eb2","key":"jira.project.issue.view-issue","navigationType":0,"readyForUser":868.4000000953674,"redirectCount":0,"resourceLoadedEnd":643.4000000953674,"resourceLoadedStart":290.2000000476837,"resourceTiming":[{"duration":63.700000047683716,"initiatorType":"link","name":"https://jira.workterra.net/s/3003653444a1e1a85555cab7dcfb3a21-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/2e46d90b5cae895c9c38649c9d510130/_/download/contextbatch/css/_super/batch.css","startTime":290.2000000476837,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":290.2000000476837,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":353.90000009536743,"responseStart":0,"secureConnectionStart":0},{"duration":63.60000002384186,"initiatorType":"link","name":"https://jira.workterra.net/s/dd6a0911920485696ac20493290df627-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/3abe50d469404b639745df44b51476b6/_/download/contextbatch/css/jira.browse.project,jira.view.issue,project.issue.navigator,jira.global,atl.general,-_super/batch.css?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&richediton=true","startTime":290.5,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":290.5,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":354.10000002384186,"responseStart":0,"secureConnectionStart":0},{"duration":64,"initiatorType":"link","name":"https://jira.workterra.net/s/d41d8cd98f00b204e9800998ecf8427e-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/8.5.0/_/download/batch/com.atlassian.auiplugin:split_aui.pattern.label/com.atlassian.auiplugin:split_aui.pattern.label.css","startTime":290.7000000476837,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":290.7000000476837,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":354.7000000476837,"responseStart":0,"secureConnectionStart":0},{"duration":64.60000002384186,"initiatorType":"link","name":"https://jira.workterra.net/s/bd548f27bbf8f278bd83b60dd3284ed8-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/1.0/_/download/batch/jira.webresources:global-static-adgs/jira.webresources:global-static-adgs.css","startTime":290.8000000715256,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":290.8000000715256,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":355.40000009536743,"responseStart":0,"secureConnectionStart":0},{"duration":65.09999990463257,"initiatorType":"link","name":"https://jira.workterra.net/s/70725731a158a7140f19ddbd4201ba27-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/1.0/_/download/batch/jira.webresources:global-static/jira.webresources:global-static.css","startTime":290.90000009536743,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":290.90000009536743,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":356,"responseStart":0,"secureConnectionStart":0},{"duration":211.80000007152557,"initiatorType":"script","name":"https://jira.workterra.net/s/f2623af22c15df767ec6ff268ae0b8bd-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/2e46d90b5cae895c9c38649c9d510130/_/download/contextbatch/js/_super/batch.js?locale=en-US","startTime":291.10000002384186,"connectEnd":291.10000002384186,"connectStart":291.10000002384186,"domainLookupEnd":291.10000002384186,"domainLookupStart":291.10000002384186,"fetchStart":291.10000002384186,"redirectEnd":0,"redirectStart":0,"requestStart":361.3000000715256,"responseEnd":502.90000009536743,"responseStart":397.8000000715256,"secureConnectionStart":291.10000002384186},{"duration":351.60000002384186,"initiatorType":"script","name":"https://jira.workterra.net/s/6ce676f2a5bcc9651cef6e7956f05def-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/3abe50d469404b639745df44b51476b6/_/download/contextbatch/js/jira.browse.project,jira.view.issue,project.issue.navigator,jira.global,atl.general,-_super/batch.js?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&locale=en-US&richediton=true","startTime":291.8000000715256,"connectEnd":291.8000000715256,"connectStart":291.8000000715256,"domainLookupEnd":291.8000000715256,"domainLookupStart":291.8000000715256,"fetchStart":291.8000000715256,"redirectEnd":0,"redirectStart":0,"requestStart":362.5,"responseEnd":643.4000000953674,"responseStart":423.10000002384186,"secureConnectionStart":291.8000000715256},{"duration":158.5,"initiatorType":"script","name":"https://jira.workterra.net/s/ecf7ec549751ae117b778f0525d6d371-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/4.1.5/_/download/resources/com.atlassian.plugins.atlassian-chaperone:hotspot-tour/hotspot-tour.js?batch=false&locale=en-US","startTime":291.90000009536743,"connectEnd":291.90000009536743,"connectStart":291.90000009536743,"domainLookupEnd":291.90000009536743,"domainLookupStart":291.90000009536743,"fetchStart":291.90000009536743,"redirectEnd":0,"redirectStart":0,"requestStart":363.90000009536743,"responseEnd":450.40000009536743,"responseStart":449.7000000476837,"secureConnectionStart":291.90000009536743},{"duration":159,"initiatorType":"script","name":"https://jira.workterra.net/s/6aa3fcf1fac5fd551eee0b69077524e6-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/aae1242f5fc81cc6a5bb8bc963ccda29/_/download/contextbatch/js/atl.global,-_super/batch.js?locale=en-US","startTime":292,"connectEnd":292,"connectStart":292,"domainLookupEnd":292,"domainLookupStart":292,"fetchStart":292,"redirectEnd":0,"redirectStart":0,"requestStart":365.2000000476837,"responseEnd":451,"responseStart":450.40000009536743,"secureConnectionStart":292},{"duration":159.39999997615814,"initiatorType":"script","name":"https://jira.workterra.net/s/d41d8cd98f00b204e9800998ecf8427e-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/1.0/_/download/batch/jira.webresources:calendar-en/jira.webresources:calendar-en.js","startTime":292.10000002384186,"connectEnd":292.10000002384186,"connectStart":292.10000002384186,"domainLookupEnd":292.10000002384186,"domainLookupStart":292.10000002384186,"fetchStart":292.10000002384186,"redirectEnd":0,"redirectStart":0,"requestStart":373.90000009536743,"responseEnd":451.5,"responseStart":451.10000002384186,"secureConnectionStart":292.10000002384186},{"duration":159.89999997615814,"initiatorType":"script","name":"https://jira.workterra.net/s/d41d8cd98f00b204e9800998ecf8427e-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/1.0/_/download/batch/jira.webresources:calendar-localisation-moment/jira.webresources:calendar-localisation-moment.js","startTime":292.2000000476837,"connectEnd":292.2000000476837,"connectStart":292.2000000476837,"domainLookupEnd":292.2000000476837,"domainLookupStart":292.2000000476837,"fetchStart":292.2000000476837,"redirectEnd":0,"redirectStart":0,"requestStart":376.10000002384186,"responseEnd":452.10000002384186,"responseStart":451.60000002384186,"secureConnectionStart":292.2000000476837},{"duration":160.29999995231628,"initiatorType":"script","name":"https://jira.workterra.net/s/ecf7ec549751ae117b778f0525d6d371-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/8.5.0/_/download/batch/com.atlassian.auiplugin:split_aui.pattern.label/com.atlassian.auiplugin:split_aui.pattern.label.js?locale=en-US","startTime":292.3000000715256,"connectEnd":292.3000000715256,"connectStart":292.3000000715256,"domainLookupEnd":292.3000000715256,"domainLookupStart":292.3000000715256,"fetchStart":292.3000000715256,"redirectEnd":0,"redirectStart":0,"requestStart":377.10000002384186,"responseEnd":452.60000002384186,"responseStart":452.2000000476837,"secureConnectionStart":292.3000000715256},{"duration":84.29999995231628,"initiatorType":"link","name":"https://jira.workterra.net/s/05c862146699bb029ceb0a489075e63b-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/bcd66e9a133a1b9f5fd14b56841e1c5b/_/download/contextbatch/css/jira.global.look-and-feel,-_super/batch.css","startTime":292.40000009536743,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":292.40000009536743,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":376.7000000476837,"responseStart":0,"secureConnectionStart":0},{"duration":160.80000007152557,"initiatorType":"script","name":"https://jira.workterra.net/rest/api/1.0/shortcuts/805012/344f6dde0e779bc821c159302c8a4389/shortcuts.js?context=issuenavigation&context=issueaction","startTime":292.5,"connectEnd":292.5,"connectStart":292.5,"domainLookupEnd":292.5,"domainLookupStart":292.5,"fetchStart":292.5,"redirectEnd":0,"redirectStart":0,"requestStart":378.7000000476837,"responseEnd":453.3000000715256,"responseStart":452.8000000715256,"secureConnectionStart":292.5},{"duration":84.80000007152557,"initiatorType":"link","name":"https://jira.workterra.net/s/9095228fa10daa2d3e3d7d5760c95e91-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/72477c22780abda5f51fe696920d843f/_/download/contextbatch/css/com.atlassian.jira.projects.sidebar.init,-_super,-jira.view.issue,-project.issue.navigator/batch.css?jira.create.linked.issue=true&richediton=true","startTime":292.60000002384186,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":292.60000002384186,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":377.40000009536743,"responseStart":0,"secureConnectionStart":0},{"duration":163.10000002384186,"initiatorType":"script","name":"https://jira.workterra.net/s/c19a1b46e985d7fb85efaf27c8febfdd-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/72477c22780abda5f51fe696920d843f/_/download/contextbatch/js/com.atlassian.jira.projects.sidebar.init,-_super,-jira.view.issue,-project.issue.navigator/batch.js?jira.create.linked.issue=true&locale=en-US&richediton=true","startTime":292.7000000476837,"connectEnd":292.7000000476837,"connectStart":292.7000000476837,"domainLookupEnd":292.7000000476837,"domainLookupStart":292.7000000476837,"fetchStart":292.7000000476837,"redirectEnd":0,"redirectStart":0,"requestStart":381.2000000476837,"responseEnd":455.8000000715256,"responseStart":453.40000009536743,"secureConnectionStart":292.7000000476837},{"duration":217.5,"initiatorType":"script","name":"https://jira.workterra.net/s/d41d8cd98f00b204e9800998ecf8427e-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/1.0/_/download/batch/jira.webresources:bigpipe-js/jira.webresources:bigpipe-js.js","startTime":315.60000002384186,"connectEnd":315.60000002384186,"connectStart":315.60000002384186,"domainLookupEnd":315.60000002384186,"domainLookupStart":315.60000002384186,"fetchStart":315.60000002384186,"redirectEnd":0,"redirectStart":0,"requestStart":466,"responseEnd":533.1000000238419,"responseStart":532.6000000238419,"secureConnectionStart":315.60000002384186},{"duration":306.7999999523163,"initiatorType":"script","name":"https://jira.workterra.net/s/d41d8cd98f00b204e9800998ecf8427e-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/1.0/_/download/batch/jira.webresources:bigpipe-init/jira.webresources:bigpipe-init.js","startTime":315.7000000476837,"connectEnd":315.7000000476837,"connectStart":315.7000000476837,"domainLookupEnd":315.7000000476837,"domainLookupStart":315.7000000476837,"fetchStart":315.7000000476837,"redirectEnd":0,"redirectStart":0,"requestStart":516.6000000238419,"responseEnd":622.5,"responseStart":621.9000000953674,"secureConnectionStart":315.7000000476837},{"duration":58.10000002384186,"initiatorType":"xmlhttprequest","name":"https://jira.workterra.net/rest/webResources/1.0/resources","startTime":641.8000000715256,"connectEnd":641.8000000715256,"connectStart":641.8000000715256,"domainLookupEnd":641.8000000715256,"domainLookupStart":641.8000000715256,"fetchStart":641.8000000715256,"redirectEnd":0,"redirectStart":0,"requestStart":666.5,"responseEnd":699.9000000953674,"responseStart":699.2000000476837,"secureConnectionStart":641.8000000715256},{"duration":64.60000002384186,"initiatorType":"xmlhttprequest","name":"https://jira.workterra.net/rest/webResources/1.0/resources","startTime":737,"connectEnd":737,"connectStart":737,"domainLookupEnd":737,"domainLookupStart":737,"fetchStart":737,"redirectEnd":0,"redirectStart":0,"requestStart":763.9000000953674,"responseEnd":801.6000000238419,"responseStart":801,"secureConnectionStart":737}],"threshold":1000,"fetchStart":0,"domainLookupStart":0,"domainLookupEnd":0,"connectStart":0,"connectEnd":0,"requestStart":177,"responseStart":261,"responseEnd":315,"domLoading":265,"domInteractive":910,"domContentLoadedEventStart":910,"domContentLoadedEventEnd":955,"domComplete":1137,"loadEventStart":1137,"loadEventEnd":1139,"userAgent":"Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com)","marks":[],"measures":[],"correlationId":"19d7091707b7ac","effectiveType":"4g","downlink":10,"rtt":0,"serverDuration":55,"dbReadsTimeInMs":11,"dbConnsTimeInMs":12,"applicationHash":"156decd7d2b4272533aa6cefc8294af635e1da97","experiments":[]}}