Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Jira renders HTML/JavaScript in fields leading to XSS

Gummadi_ SivaSandeep July 24, 2024

Is there any option to block the fields for Incident response Tickets while entering the IPS address and URLS. As i was entering the ip address and Ticket URLS the URL is re-directing to malicious Website.

1 answer

1 vote
Nikola Perisic
Community Champion
July 24, 2024

Welcome @Gummadi_ SivaSandeep 

Are you referring to your service management project? And also, report this issue to the Atlassian as well, if it's XSS then it's a security issue.

Gummadi_ SivaSandeep July 24, 2024

yes i am referring to my JIRA-Service management project and XSS is a Security Issue

Nikola Perisic
Community Champion
July 24, 2024

You have two options here: either to remove the field causing the security issue or to apply the issue security levels. The first option here is the best, since it is causing a much higher risk.Please report this to Atlassian.

Ali Mohammed Afar
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
July 24, 2024

All service 

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events