I want to use Text gadget in jira to write some text and link websites on my dashboard But It says, Enabling text gadget makes jira instance vulnerable to XSS attacks. Is that okay to enable the text gadget on 7.12.3? Is that vulnerability still there?
My assumption is, the vulnerability still would be there irrespective of jira version since it may contains plain HTML code. Please confirm.
You are right - it remains vulnerable.
@Nic Brough -Adaptavist- Thanks for confirming, Nic. I could see that there is alternative solution for JIRA cloud - Rich Text Gadget for Jira
Do we have something like that for JIRA Server??
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Online forums and learning are now in one easy-to-use experience.
By continuing, you accept the updated Community Terms of Use and acknowledge the Privacy Policy. Your public name, photo, and achievements may be publicly visible and available in search engines.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.