Set up the Jira integration | Fluid Attacks

Set up the Jira integration

Info on account to use for Jira integration
The following are steps to set up the latest integration. Find the documentation on setting up the previous release at the bottom of this page.
Advice on Jira integration setup
Have someone with a User Manager role and access to the most groups in your organization set up this integration. The connection is made with the groups this person has access to.
After you have installed the Fluid Attacks app for Jira Cloud, follow these steps to set up the integration:
  1. From the top menu, click on Apps and then Manage your apps.
  2. Manage apps to set up the Fluid Attacks Jira integration

  3. Click on the Settings option for the Fluid Attacks app.
  4. Access settings of the Fluid Attacks app on Jira

  5. Provide the Fluid Attacks API token and click Connect. To learn how to get this token on Fluid Attacks’ platform, read Generate or revoke the API token.

  6. Carefully read Fluid Attacks' disclaimer. Please bear in mind that you are agreeing to Atlassian's data policies. Click on Confirm to proceed.
  7. Read and agree to Atlassian data policies

  8. When the screen shows successful authentication, you can connect security containers (i.e., groups). Within your Jira project, go to Security and click Finish setup.
  9. Authenticate to Jira with the Fluid Attacks API tokenSuccessful authentication

    Finish setup of the Fluid Attacks app on JiraFinish setup option

  10. Under Connected tools, find the Fluid Attacks app and click on Connect security containers.
  11. Connect organizations in the Fluid Attacks Jira integration

  12. Under Connect security containers, click on your organization's name.
  13. Connect security containers in the Fluid Attacks Jira integration

  14. Select the intended group(s) and click on Connect.
  15. Connect groups in the Fluid Attacks Jira integration

  16. Wait up to a few minutes while Jira retrieves the vulnerabilities reported in the platform.

When the reported vulnerabilities start appearing, you can see their details and the options to link to a Jira issue or create a Jira issue to link.

Previous release

Warning on outdated release
A more recent release is available. You are advised to install it and follow the steps above.
Info on required permissions
Permissions required: To set up this integration, you need the permission “Administer Jira” on Jira Cloud.
After you have installed the Fluid Attacks app for Jira Cloud, follow these steps to set up the integration:
  1. Open the Jira project that you wish to connect with Fluid Attacks’ platform.
  2. Open the Jira project to connect with the Fluid Attacks platform

  3. Select Fluid Attacks under APPS in the left-hand menu.
  4. Find the Fluid Attacks app on the Jira menu

  5. You will get a message with the path to set up the Fluid Attacks app.
  6. Find the path on Jira to set up the Fluid Attacks app

  7. Provide the Fluid Attacks API token in the screen shown below and click Connect. To learn how to get this token on Fluid Attacks’ platform, read Generate or revoke the API token.
  8. Provide the Fluid Attacks API token on Jira
    Note on required role
    Note: To generate the API token your client role on Fluid Attacks’ platform must be either User, Vulnerability Manager or User Manager.
  9. Select the corresponding group on Fluid Attacks' platform and click Save. You will get a “Settings saved” message confirming the process was successful.
  10. Choose the Fluid Attacks group to integrate with Jira
Upon clicking on Back to project, you will be directed to the section of your project dedicated to the Fluid Attacks app. There, if you are the Jira instance admin or have the permission "Administer Jira," you can see the reported vulnerabilities with their details and the options to link to a Jira issue or create a Jira issue to link.
Note on required permissions
Note: To access linked vulnerabilities and request reattacks on Jira Cloud, you must have the permission to assign or be assigned issues.
Free trial message
Free trial
Search for vulnerabilities in your apps for free with Fluid Attacks' automated security testing! Start your 21-day free trial and discover the benefits of the Continuous Hacking Essential plan. If you prefer the Advanced plan, which includes the expertise of Fluid Attacks' hacking team, fill out this contact form.