Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Has anyone had any security issues or concerns related to usage of Jira Cloud Forms?

James Woyciesjes
Contributor
November 20, 2025

We are considering utilizing the Forms feature to capture input/feedback from non-Jira users. There are only 2 level of access for forms. Jira users or completely public. i.e. anyone with the link can submit. Wondering if anyone has had any security related issues or concerns with the public access.

3 answers

1 accepted

0 votes
Answer accepted
John Funk
Community Champion
November 20, 2025

Hi James,

You might consider setting up a Jira Service Management project to capture the intake and then create an automation rule to clone the request into your software project. You have way more and better options of controlling who can access the form that way. 

0 votes
Olha Yevdokymova_SaaSJet
Atlassian Partner
November 30, 2025

Hi @James Woyciesjes 

You’re correct: in Jira Cloud there are currently only two visibility levels for native forms:

  • Jira users → authenticated users in your instance.

  • Public access → anyone with the link can view and submit.

Because public forms don’t require authentication, it’s true that they can be submitted anonymously and are potentially open to spam or misuse if the link is shared widely. Jira’s native forms don’t include extra security controls like CAPTCHA, IP restrictions, or domain whitelisting at this point.

Common Security Concerns with Public Jira Forms

  • Spam or bot submissions: Since there’s no CAPTCHA or verification, you can receive junk data if the link is exposed.

  • Sensitive data exposure: Users can accidentally submit confidential information through an unsecured link.

  • Auditability: There’s no clear submitter identity unless you include a required “Name/Email” field in the form.

To mitigate this, most teams either:

  • Use public forms only for low-risk data collection (e.g., feedback, surveys).

  • Gate access behind a portal (for authenticated Jira Service Management requests).

 If You Need More Control

If you’re planning to collect structured data from external or internal users but want more control over security and submission tracking, you might look at Smart Forms for Jira (developed by my team). It adds some extra layers beyond what native Jira Forms provide:

  • Restricted external sharing: You can share forms publicly or limit access to “verified in your instance” users — no need to expose everything.

  • Form expiration & single-response links: For sensitive workflows (e.g., approvals), each link can allow one submission only and expires after 30 days.

  • Form editing restrictions: You can control who can view, edit, or download responses internally.

  • Captcha protection included
  • Audit trail: Every submission is stored in a linked Jira issue, so you retain full traceability even for external responses.

  • Optional embedding: You can safely embed forms into your service portal or website without revealing direct submission URLs.

In short:

  • Native Jira Forms are safe for general use but limited — there’s no CAPTCHA or access granularity beyond “public” or “Jira users.”

  • For more controlled, auditable submissions, tools like Smart Forms for Jira add restricted access, one-time links, and internal audit visibility — all while keeping responses securely tied to Jira work items.

James Woyciesjes
Contributor
December 9, 2025

I found this page: How secure are public forms? | Jira Cloud | Atlassian Support and it says that Jira Forms is using reCAPTCHA now, plus there is malware screening from what I am to understand for Jira/Conf cloud. I am having a security test run to evaluate if we want to use or not.

Thank you for the info on Smart Forms for Jira.

Like John Funk likes this
0 votes
Nikola Perisic
Community Champion
November 20, 2025

Hi @James Woyciesjes 

I would suggest only sharing the Public forms with the users that you are intending to share. Probability of someone guessing the URL of your form is low. I also believe that these forms are protected from the web app based attacks such as XXS, SQL injection and more. Only send the public forms to the trusted users. 

Suggest an answer

Log in or Sign up to answer
DEPLOYMENT TYPE
CLOUD
PRODUCT PLAN
ENTERPRISE
PERMISSIONS LEVEL
Product Admin
TAGS
AUG Leaders

Atlassian Community Events