Are you in the loop? Keep up with the latest by making sure you're subscribed to Community Announcements. Just click Watch and select Articles.

×
Create
cancel
Showing results for 
Search instead for 
Did you mean: 
Sign up Log in
Celebration

Earn badges and make progress

You're on your way to the next level! Join the Kudos program to earn points and save your progress.

Deleted user Avatar
Deleted user

Level 1: Seed

25 / 150 points

Next: Root

Avatar

1 badge earned

Collect

Participate in fun challenges

Challenges come and go, but your rewards stay with you. Do more to earn more!

Challenges
Coins

Gift kudos to your peers

What goes around comes around! Share the love by gifting kudos to your peers.

Recognition
Ribbon

Rise up in the ranks

Keep earning points to reach the top of the leaderboard. It resets every quarter so you always have a chance!

Leaderboard

Text gadget in jira

Hi all,

I want to use Text gadget in jira to write some text and link websites on my dashboard but enabling text gadget makes jira instance vulnerable to XSS attacks. Is that okay to enable the text gadget? Can someone suggest me please.
Thank you

2 answers

2 accepted

10 votes
Answer accepted
Javi
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
Apr 19, 2018 • edited

 

Alternatively, you can create an issue within Jira and add your text/links to the Description field of an issue. Once you do this, create a filter based on the newly created issue 

ex:

issue = "ABC-1"

Next, go to your dashboard and add a Filter Results gadget and select your newly created filter based. For the section Columns to display, select only Description and save. 

You should now see your text/links. 

Regards,

Javier A. 

I tried this. A good alternative solution. Thank you so much

thanks Javier.   your solution although a hack, works.  much appreciated.

Thank you for the alternative solution

4 votes
Answer accepted
joshloe
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
Apr 18, 2018 • edited

Samanth,

 

In regards to your question, that is really up to a personal preference.   The Text Gadget is disabled by default because it is a potential security risk, as it can contain arbitrary HTML which could potentially make your JIRA system vulnerable to XSS attacks as stated in our documentation Adding the Text Gadget.

That being said, the risk can really depends on your usage.  If you are running on a local network only and you trust your users to not abuse the gadget, then it should be okay to be used in your JIRA.

Again, this is something that you'll have to weigh the pros and cons about.   There are a few listings in our marketplace for Rich Text add-ons, that might be worth taking a look at to see if they are able to replace the functionality in the Text Gadget.

In JIRA Cloud we've removed the Text Gadget to avoid any potential security risks and suggest users look into the Rich Text Gadget on our Marketplace.

I hope this helps answer your question Samanth.

 

- Josh Loe

Thank you so much for your help

the Atlassian "Rich Text Gadget for Jira" doesn't appear work for Jira Cloud.    It installs ok, but isn't visible under the available gadgets.

What about the server version? Are there any secure alternatives to the Text Gadget?

@joshloe, is there another option to the Rich Text Gadget now that this gadget appears to no longer be found in the Marketplace?

Like # people like this

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events