Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Is it safe to enable Text Gadget on JIRA Server 7.12.3??

nallu July 14, 2019

I want to use Text gadget in jira to write some text and link websites on my dashboard But It says, Enabling text gadget makes jira instance vulnerable to XSS attacks. Is that okay to enable the text gadget on 7.12.3? Is that vulnerability still there? 

My assumption is, the vulnerability still would be there irrespective of jira version since it may contains plain HTML code. Please confirm. 

1 answer

1 accepted

0 votes
Answer accepted
Nic Brough -Adaptavist-
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
July 14, 2019

You are right - it remains vulnerable.

nallu July 14, 2019

@Nic Brough -Adaptavist- Thanks for confirming, Nic. I could see that there is alternative solution for JIRA cloud - Rich Text Gadget for Jira 

Do we have something like that for JIRA Server?? 

Suggest an answer

Log in or Sign up to answer