Filter for announcement banner in JIRA7.0

manojkumar3036 March 19, 2018

Hi All,

I want to apply a filter for the announcement banner in JIRA as the JIRA application allows any login user to inject any kind of java script for open redirection, general configuration or System Announcement. So there can be XSS attack!!. I want to prevent the script injection in those announcement banner, general configuration or system announcement areas. 

1 answer

1 accepted

2 votes
Answer accepted
Fazila Ashraf
Community Leader
Community Leader
Community Leaders are connectors, ambassadors, and mentors. On the online community, they serve as thought leaders, product experts, and moderators.
April 10, 2018

Hi @manojkumar3036

You are mistaken. Jira just doesnt allow 'any' logged in user to update the announcement banner. 

It allows only the JIRA administrators to do that.

Fazila Ashraf
Community Leader
Community Leader
Community Leaders are connectors, ambassadors, and mentors. On the online community, they serve as thought leaders, product experts, and moderators.
April 11, 2018

Hi @manojkumar3036, If my answer helped, you can choose to accept the answer (The tick mark just before my answer) :)

Suggest an answer

Log in or Sign up to answer