Modify Attachment Security Policy
Platform Notice: Server and Data Center Only - This article only applies to Atlassian products on the server and data center platforms.
Modify the Attachment Security Policy to control how attachments are handled within Jira, by either forcing the download of an attachment or displaying it inline.
The attachment settings can be modified within the Jira configuration.
- Navigate to 'Jira Administration -> System'.
- Select the 'Edit Settings' button near the top right corner.
- Locate the option 'Internet Explorer MIME Sniffing Security Hole Workaround Policy'.
- Insecure: inline display of attachments
- Secure: forced download of attachments for all browsers
- Work around Internet Explorer security hole
Attachment viewing security options for cross-site site scripting vulnerabilities present in Internet Explorer 7 and earlier. Use the workaround to reduce the risk of attacks to IE users via attachments. Use download-only mode to sacrifice attachment viewing convenience in all browsers and gain ultimate protection against hostile attachments. See JIRA Security Advisory 2008-08-26