Text gadget in jira

Sam April 18, 2018
Hi all,

I want to use Text gadget in jira to write some text and link websites on my dashboard but enabling text gadget makes jira instance vulnerable to XSS attacks. Is that okay to enable the text gadget? Can someone suggest me please.
Thank you

2 answers

2 accepted

11 votes
Answer accepted
Javi
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
April 19, 2018

 

Alternatively, you can create an issue within Jira and add your text/links to the Description field of an issue. Once you do this, create a filter based on the newly created issue 

ex:

issue = "ABC-1"

Next, go to your dashboard and add a Filter Results gadget and select your newly created filter based. For the section Columns to display, select only Description and save. 

You should now see your text/links. 

Regards,

Javier A. 

Sam May 1, 2018

I tried this. A good alternative solution. Thank you so much

Jira Automation October 15, 2018

thanks Javier.   your solution although a hack, works.  much appreciated.

Shantala Ramesh May 4, 2022

Thank you for the alternative solution

4 votes
Answer accepted
joshloe
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
April 18, 2018

Samanth,

 

In regards to your question, that is really up to a personal preference.   The Text Gadget is disabled by default because it is a potential security risk, as it can contain arbitrary HTML which could potentially make your JIRA system vulnerable to XSS attacks as stated in our documentation Adding the Text Gadget.

That being said, the risk can really depends on your usage.  If you are running on a local network only and you trust your users to not abuse the gadget, then it should be okay to be used in your JIRA.

Again, this is something that you'll have to weigh the pros and cons about.   There are a few listings in our marketplace for Rich Text add-ons, that might be worth taking a look at to see if they are able to replace the functionality in the Text Gadget.

In JIRA Cloud we've removed the Text Gadget to avoid any potential security risks and suggest users look into the Rich Text Gadget on our Marketplace.

I hope this helps answer your question Samanth.

 

- Josh Loe

Sam May 1, 2018

Thank you so much for your help

Jira Automation October 15, 2018

the Atlassian "Rich Text Gadget for Jira" doesn't appear work for Jira Cloud.    It installs ok, but isn't visible under the available gadgets.

Andrea Roßkamp [Communardo] January 4, 2019

What about the server version? Are there any secure alternatives to the Text Gadget?

Jennifer Meacham January 27, 2019

@joshloe, is there another option to the Rich Text Gadget now that this gadget appears to no longer be found in the Marketplace?

Like # people like this

Suggest an answer

Log in or Sign up to answer