Create
cancel
Showing results for 
Search instead for 
Did you mean: 
Sign up Log in

Jira renders HTML/JavaScript in fields leading to XSS

Gummadi_ SivaSandeep July 24, 2024

Is there any option to block the fields for Incident response Tickets while entering the IPS address and URLS. As i was entering the ip address and Ticket URLS the URL is re-directing to malicious Website.

1 answer

1 vote
Nikola Perisic
Community Leader
Community Leader
Community Leaders are connectors, ambassadors, and mentors. On the online community, they serve as thought leaders, product experts, and moderators.
July 24, 2024

Welcome @Gummadi_ SivaSandeep 

Are you referring to your service management project? And also, report this issue to the Atlassian as well, if it's XSS then it's a security issue.

Gummadi_ SivaSandeep July 24, 2024

yes i am referring to my JIRA-Service management project and XSS is a Security Issue

Nikola Perisic
Community Leader
Community Leader
Community Leaders are connectors, ambassadors, and mentors. On the online community, they serve as thought leaders, product experts, and moderators.
July 24, 2024

You have two options here: either to remove the field causing the security issue or to apply the issue security levels. The first option here is the best, since it is causing a much higher risk.Please report this to Atlassian.

Ali Mohammed Afar
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
July 24, 2024

All service 

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events