Create
cancel
Showing results for 
Search instead for 
Did you mean: 
Sign up Log in

Enable XSS protection in HTML or HTML include Macro

Umang January 12, 2021

Hello,

        We would like to use the HTML or HTML include macro for our confluence instance

https://confluence.atlassian.com/conf74/html-macro-1003128855.html

https://confluence.atlassian.com/conf74/html-include-macro-1003128854.html

 

Both of these macro pose the risk of XSS vulnerability. We are using version 7.4.1 . Is there a way to use these macros and avoid the risk of XSS. I read some older articles about disabling JS. Is this available in Server version 7.4.1 ?

 

Our use case is to be able to include Google Docs in the confluence. So if there is a suggestion for another macro or FREE solution to achieve inclusion of Google Docs without the use of HTML macro / risk of XSS, would be open to that suggestion as well.

 

 

1 answer

0 votes
Thiago Masutti
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
January 12, 2021

Hi @Umang 

Both macros can make your environment vulnerable, even on the latest version of Confluence.

If security is must on your environment, it would be better to rely on a Supported App available on Atlassian Marketplace.

There are at least 3 options that may fit your use case: https://marketplace.atlassian.com/search?hosting=server&moreFilters=vendorSupported&product=confluence&query=google%20drive

 

Kind regards,
Thiago Masutti

Umang January 12, 2021

Hi @Thiago Masutti 

Thank you for the response. So is there no way to disable Javascript or script encoding or escaping which would stop execution of Javascript when using either of the HTML macros?

 

Alternatively, is there a way to enable the macros for specific users only ? 

 

Thank you for the link to the marketplace apps. However looks like they are all paid apps, which may not be an option for us right now.

 

Regards

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events