Enterprise Edition
Integrating Burp Suite Enterprise Edition with Jira
-
Last updated: June 6, 2024
-
Read time: 3 Minutes
If you or your teams use Jira, you may like to integrate this with Burp Suite Enterprise Edition. Once configured, this enables you to create Jira tickets from directly within Burp Suite Enterprise Edition for any security vulnerabilities found by your scans. Integration is supported for both Jira Cloud and Jira Data Center.
Supported versions of Jira
Burp Suite Enterprise Edition supports integration with the following versions of Jira Cloud and Jira Data Center:
- Jira 9.x
- Jira 8.x
Jira 7.x and earlier are not compatible with Burp Suite Enterprise Edition.
Supported certificate types
When integrating Jira with Burp Suite Enterprise Edition, make sure that your Jira instance uses the right type of certificate for your deployment model:
SaaS deployments: Your Jira instance must use a CA-signed certificate.
On-premise deployments (standard and Kubernetes): Your Jira instance can use either a CA-signed or a self-signed certificate. To upload or delete certificates, go to Settings > Network > Manage certificates.
(Recommended) Create a new Jira user for the integration
To integrate with Jira, Burp Suite Enterprise Edition must be linked to a specific Jira user.
All Jira projects that the user has permission to create tickets in will be exposed to Burp Suite Enterprise Edition. For this reason, we recommend creating a new Jira user specifically for the integration.
Generate a Jira API token (Jira Cloud only)
If you want to integrate a cloud-based Jira installation, you first need to create a Jira API token. Burp Suite Enterprise Edition uses this to authenticate itself with Jira.
- Log in to Jira as the user that you want to use for the integration.
- In Jira, click your user icon and open your account settings.
- From the account settings page, select Security.
- Click Create and manage API tokens.
- Click Create API token.
- Enter a label for the token and click Create.
- Copy the token to your clipboard and save it somewhere secure.
Note
You will not be able to view or copy this token again once you close the popup.
Connect Burp Suite Enterprise Edition to Jira
To connect Burp Suite Enterprise Edition to Jira:
- Log in to Burp Suite Enterprise Edition as an administrator.
- From the settings menu, select Integrations.
- On the Jira tile, select Configure.
- Enter the URL for your Jira server in the Jira URL field.
-
Click Continue.
- The next step depends on whether you use Jira Cloud or Jira Data Center:
- For Jira Cloud, enter the email address and the API token of the Jira user that you created earlier. Click Continue.
- For Jira Data Center, enter the username and password of the Jira user that you created earlier. Click Continue.
If Burp Suite Enterprise Edition successfully connects to Jira, you'll be presented with options to configure both manual and automatic ticket creation.
Note
You must enable at least one of these in order to complete the Jira configuration.
Enable manual Jira ticket creation
To enable users to create Jira tickets manually from within Burp Suite Enterprise Edition, you need to configure the list of Jira projects and ticket types that they can choose from:
- Select a project from the Project drop-down list.
- Select a ticket type from the Ticket Type drop-down list.
- Click the + symbol.
-
If necessary, repeat these steps to add more projects and ticket types.
Note
You need to add separate entries for each ticket type, even when adding multiple ticket types from the same project.
-
Click Save.
Enable automatic Jira ticket creation
You can configure Burp Suite Enterprise Edition to create Jira tickets automatically. Tickets are created for any issues that meet the minimum severity and confidence levels that you specify.
Note
To avoid inadvertently flooding your Jira backlog with an overwhelming number of tickets, we recommend setting high severity and confidence levels initially. You can then lower these once you have a better understanding of how many tickets are created as a result of your scans.
- Click Enable.
- Select a project from the Project drop-down list.
- Select a ticket type from the Ticket Type drop-down list.
- Use the sliders to set the minimum issue severity and confidence levels that trigger Jira ticket creation.
-
Click Save.
Manually creating Jira tickets
For information on how users can manually create Jira tickets, refer to Raise Jira tickets from within Burp Suite Enterprise Edition.