-
Type:
Enhancement
-
Status:
Closed
-
Priority:
Medium
-
Resolution:
Unresolved
-
-
-
Module:
BenAdmin
- Security
-
-
Item State:
Production Complete
- Closed
Vulnerability Description
Transport Layer Security (TLS) version 1.0 has been found to contain protocol-level weaknesses.
Impact
Given the theoretical nature of attacks on TLS 1.0, supporting TLS 1.0 is not a risk-oriented decision. That being said, history has shown that as cryptographic attacks age, they get stronger (i.e. easier to exploit).
Verification and Attack Information
Praetorian verified the TLS v1.0 protocol was enabled on the application server using SSLScan, an automated SSL/TLS scanning tool. The application server accepted the TLS v1.0 protocol, as shown in the images below.
Recommendation
Praetorian recommends following Mozilla’s SSL/TLS (see reference below) configuration suggestions as a guide for ciphersuite support. These configurations provide high-security and high-availability to SSL/TLS clients.
References
https://mozilla.github.io/server-side-tls/ssl-config-generator/
https://cipherli.st/
https://www.wolfssl.com/wolfSSL/Blog/Entries/2010/12/14_A_Comparison_of_TLS_1.1_and_TLS_1.2.html
No work has yet been logged on this issue.
{"report":{"apdex":1,"isInitial":true,"journeyId":"d466e320-6e03-4555-9e35-270e61c2b1c1","key":"jira.project.issue.view-issue","navigationType":0,"readyForUser":677.7000007629395,"redirectCount":0,"resourceLoadedEnd":537.8000011444092,"resourceLoadedStart":180,"resourceTiming":[{"duration":10,"initiatorType":"link","name":"https://jira.workterra.net/s/3003653444a1e1a85555cab7dcfb3a21-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/2e46d90b5cae895c9c38649c9d510130/_/download/contextbatch/css/_super/batch.css","startTime":180,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":180,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":190,"responseStart":0,"secureConnectionStart":0},{"duration":10.399999618530273,"initiatorType":"link","name":"https://jira.workterra.net/s/dd6a0911920485696ac20493290df627-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/3abe50d469404b639745df44b51476b6/_/download/contextbatch/css/jira.browse.project,jira.view.issue,project.issue.navigator,jira.global,atl.general,-_super/batch.css?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&richediton=true","startTime":180.30000114440918,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":180.30000114440918,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":190.70000076293945,"responseStart":0,"secureConnectionStart":0},{"duration":16.200000762939453,"initiatorType":"link","name":"https://jira.workterra.net/s/d41d8cd98f00b204e9800998ecf8427e-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/8.5.0/_/download/batch/com.atlassian.auiplugin:split_aui.pattern.label/com.atlassian.auiplugin:split_aui.pattern.label.css","startTime":180.39999961853027,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":180.39999961853027,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":196.60000038146973,"responseStart":0,"secureConnectionStart":0},{"duration":17.200000762939453,"initiatorType":"link","name":"https://jira.workterra.net/s/bd548f27bbf8f278bd83b60dd3284ed8-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/1.0/_/download/batch/jira.webresources:global-static-adgs/jira.webresources:global-static-adgs.css","startTime":180.39999961853027,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":180.39999961853027,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":197.60000038146973,"responseStart":0,"secureConnectionStart":0},{"duration":21.100000381469727,"initiatorType":"link","name":"https://jira.workterra.net/s/70725731a158a7140f19ddbd4201ba27-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/1.0/_/download/batch/jira.webresources:global-static/jira.webresources:global-static.css","startTime":180.60000038146973,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":180.60000038146973,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":201.70000076293945,"responseStart":0,"secureConnectionStart":0},{"duration":74.20000076293945,"initiatorType":"script","name":"https://jira.workterra.net/s/f2623af22c15df767ec6ff268ae0b8bd-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/2e46d90b5cae895c9c38649c9d510130/_/download/contextbatch/js/_super/batch.js?locale=en-US","startTime":180.60000038146973,"connectEnd":180.60000038146973,"connectStart":180.60000038146973,"domainLookupEnd":180.60000038146973,"domainLookupStart":180.60000038146973,"fetchStart":180.60000038146973,"redirectEnd":0,"redirectStart":0,"requestStart":180.60000038146973,"responseEnd":254.80000114440918,"responseStart":254.80000114440918,"secureConnectionStart":180.60000038146973},{"duration":127.89999961853027,"initiatorType":"script","name":"https://jira.workterra.net/s/6ce676f2a5bcc9651cef6e7956f05def-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/3abe50d469404b639745df44b51476b6/_/download/contextbatch/js/jira.browse.project,jira.view.issue,project.issue.navigator,jira.global,atl.general,-_super/batch.js?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&locale=en-US&richediton=true","startTime":180.80000114440918,"connectEnd":180.80000114440918,"connectStart":180.80000114440918,"domainLookupEnd":180.80000114440918,"domainLookupStart":180.80000114440918,"fetchStart":180.80000114440918,"redirectEnd":0,"redirectStart":0,"requestStart":180.80000114440918,"responseEnd":308.70000076293945,"responseStart":308.6000003814697,"secureConnectionStart":180.80000114440918},{"duration":130.80000114440918,"initiatorType":"script","name":"https://jira.workterra.net/s/ecf7ec549751ae117b778f0525d6d371-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/4.1.5/_/download/resources/com.atlassian.plugins.atlassian-chaperone:hotspot-tour/hotspot-tour.js?batch=false&locale=en-US","startTime":180.89999961853027,"connectEnd":180.89999961853027,"connectStart":180.89999961853027,"domainLookupEnd":180.89999961853027,"domainLookupStart":180.89999961853027,"fetchStart":180.89999961853027,"redirectEnd":0,"redirectStart":0,"requestStart":180.89999961853027,"responseEnd":311.70000076293945,"responseStart":311.70000076293945,"secureConnectionStart":180.89999961853027},{"duration":131.70000076293945,"initiatorType":"script","name":"https://jira.workterra.net/s/6aa3fcf1fac5fd551eee0b69077524e6-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/aae1242f5fc81cc6a5bb8bc963ccda29/_/download/contextbatch/js/atl.global,-_super/batch.js?locale=en-US","startTime":180.89999961853027,"connectEnd":180.89999961853027,"connectStart":180.89999961853027,"domainLookupEnd":180.89999961853027,"domainLookupStart":180.89999961853027,"fetchStart":180.89999961853027,"redirectEnd":0,"redirectStart":0,"requestStart":180.89999961853027,"responseEnd":312.6000003814697,"responseStart":312.6000003814697,"secureConnectionStart":180.89999961853027},{"duration":131.79999923706055,"initiatorType":"script","name":"https://jira.workterra.net/s/d41d8cd98f00b204e9800998ecf8427e-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/1.0/_/download/batch/jira.webresources:calendar-en/jira.webresources:calendar-en.js","startTime":181.10000038146973,"connectEnd":181.10000038146973,"connectStart":181.10000038146973,"domainLookupEnd":181.10000038146973,"domainLookupStart":181.10000038146973,"fetchStart":181.10000038146973,"redirectEnd":0,"redirectStart":0,"requestStart":181.10000038146973,"responseEnd":312.8999996185303,"responseStart":312.8999996185303,"secureConnectionStart":181.10000038146973},{"duration":132.10000038146973,"initiatorType":"script","name":"https://jira.workterra.net/s/d41d8cd98f00b204e9800998ecf8427e-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/1.0/_/download/batch/jira.webresources:calendar-localisation-moment/jira.webresources:calendar-localisation-moment.js","startTime":181.20000076293945,"connectEnd":181.20000076293945,"connectStart":181.20000076293945,"domainLookupEnd":181.20000076293945,"domainLookupStart":181.20000076293945,"fetchStart":181.20000076293945,"redirectEnd":0,"redirectStart":0,"requestStart":181.20000076293945,"responseEnd":313.3000011444092,"responseStart":313.3000011444092,"secureConnectionStart":181.20000076293945},{"duration":132.39999961853027,"initiatorType":"script","name":"https://jira.workterra.net/s/ecf7ec549751ae117b778f0525d6d371-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/8.5.0/_/download/batch/com.atlassian.auiplugin:split_aui.pattern.label/com.atlassian.auiplugin:split_aui.pattern.label.js?locale=en-US","startTime":181.30000114440918,"connectEnd":181.30000114440918,"connectStart":181.30000114440918,"domainLookupEnd":181.30000114440918,"domainLookupStart":181.30000114440918,"fetchStart":181.30000114440918,"redirectEnd":0,"redirectStart":0,"requestStart":181.30000114440918,"responseEnd":313.70000076293945,"responseStart":313.70000076293945,"secureConnectionStart":181.30000114440918},{"duration":132.80000114440918,"initiatorType":"link","name":"https://jira.workterra.net/s/05c862146699bb029ceb0a489075e63b-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/bcd66e9a133a1b9f5fd14b56841e1c5b/_/download/contextbatch/css/jira.global.look-and-feel,-_super/batch.css","startTime":181.39999961853027,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":181.39999961853027,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":314.20000076293945,"responseStart":0,"secureConnectionStart":0},{"duration":133.10000038146973,"initiatorType":"link","name":"https://jira.workterra.net/s/9095228fa10daa2d3e3d7d5760c95e91-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/72477c22780abda5f51fe696920d843f/_/download/contextbatch/css/com.atlassian.jira.projects.sidebar.init,-_super,-jira.view.issue,-project.issue.navigator/batch.css?jira.create.linked.issue=true&richediton=true","startTime":181.5,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":181.5,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":314.6000003814697,"responseStart":0,"secureConnectionStart":0},{"duration":132.60000038146973,"initiatorType":"script","name":"https://jira.workterra.net/rest/api/1.0/shortcuts/805012/81da1c7492d7ee698ae1cc31902498d9/shortcuts.js?context=issuenavigation&context=issueaction","startTime":181.5,"connectEnd":181.5,"connectStart":181.5,"domainLookupEnd":181.5,"domainLookupStart":181.5,"fetchStart":181.5,"redirectEnd":0,"redirectStart":0,"requestStart":181.5,"responseEnd":314.1000003814697,"responseStart":314.1000003814697,"secureConnectionStart":181.5},{"duration":133.10000038146973,"initiatorType":"script","name":"https://jira.workterra.net/s/c19a1b46e985d7fb85efaf27c8febfdd-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/72477c22780abda5f51fe696920d843f/_/download/contextbatch/js/com.atlassian.jira.projects.sidebar.init,-_super,-jira.view.issue,-project.issue.navigator/batch.js?jira.create.linked.issue=true&locale=en-US&richediton=true","startTime":181.70000076293945,"connectEnd":181.70000076293945,"connectStart":181.70000076293945,"domainLookupEnd":181.70000076293945,"domainLookupStart":181.70000076293945,"fetchStart":181.70000076293945,"redirectEnd":0,"redirectStart":0,"requestStart":181.70000076293945,"responseEnd":314.8000011444092,"responseStart":314.8000011444092,"secureConnectionStart":181.70000076293945},{"duration":302.8999996185303,"initiatorType":"script","name":"https://jira.workterra.net/s/d41d8cd98f00b204e9800998ecf8427e-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/1.0/_/download/batch/jira.webresources:bigpipe-js/jira.webresources:bigpipe-js.js","startTime":182.30000114440918,"connectEnd":182.30000114440918,"connectStart":182.30000114440918,"domainLookupEnd":182.30000114440918,"domainLookupStart":182.30000114440918,"fetchStart":182.30000114440918,"redirectEnd":0,"redirectStart":0,"requestStart":182.30000114440918,"responseEnd":485.20000076293945,"responseStart":485.20000076293945,"secureConnectionStart":182.30000114440918},{"duration":355.5,"initiatorType":"script","name":"https://jira.workterra.net/s/d41d8cd98f00b204e9800998ecf8427e-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/1.0/_/download/batch/jira.webresources:bigpipe-init/jira.webresources:bigpipe-init.js","startTime":182.30000114440918,"connectEnd":182.30000114440918,"connectStart":182.30000114440918,"domainLookupEnd":182.30000114440918,"domainLookupStart":182.30000114440918,"fetchStart":182.30000114440918,"redirectEnd":0,"redirectStart":0,"requestStart":182.30000114440918,"responseEnd":537.8000011444092,"responseStart":537.8000011444092,"secureConnectionStart":182.30000114440918},{"duration":90.89999961853027,"initiatorType":"xmlhttprequest","name":"https://jira.workterra.net/rest/webResources/1.0/resources","startTime":448.6000003814697,"connectEnd":448.6000003814697,"connectStart":448.6000003814697,"domainLookupEnd":448.6000003814697,"domainLookupStart":448.6000003814697,"fetchStart":448.6000003814697,"redirectEnd":0,"redirectStart":0,"requestStart":448.6000003814697,"responseEnd":539.5,"responseStart":539.5,"secureConnectionStart":448.6000003814697}],"threshold":1000,"fetchStart":0,"domainLookupStart":0,"domainLookupEnd":0,"connectStart":0,"connectEnd":0,"requestStart":104,"responseStart":174,"responseEnd":175,"domLoading":178,"domInteractive":715,"domContentLoadedEventStart":715,"domContentLoadedEventEnd":760,"domComplete":890,"loadEventStart":890,"loadEventEnd":892,"userAgent":"Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com)","marks":[],"measures":[],"correlationId":"cc24d08bcbdf77","effectiveType":"4g","downlink":10,"rtt":0,"serverDuration":47,"dbReadsTimeInMs":2,"dbConnsTimeInMs":3,"applicationHash":"156decd7d2b4272533aa6cefc8294af635e1da97","experiments":[]}}