scriptrunner security on public site

tmv July 28, 2015

I'm planning to install script runner on a public JIRA site.  Is there any security issues I should be concerned about?

2 answers

5 votes
JamieA
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
July 28, 2015

None known in the latest version. It does expose JQL functions to non-admins, and some time ago there was a ReDOS vulnerability in a jql function that was fixed. 

So vulns do happen, as they do in JIRA itself. 

If you're worried you might be DoSed or something, then it's probably easier to DoS someone using the provided JQL functions in SR than the native ones.

Nic Brough -Adaptavist-
Community Leader
Community Leader
Community Leaders are connectors, ambassadors, and mentors. On the online community, they serve as thought leaders, product experts, and moderators.
July 28, 2015

I'd also point out that when security issues have cropped up, Jamie fixed them *really* quickly.

2 votes
Nic Brough -Adaptavist-
Community Leader
Community Leader
Community Leaders are connectors, ambassadors, and mentors. On the online community, they serve as thought leaders, product experts, and moderators.
July 28, 2015

Not directly, it doesn't expose anything to non-admins.  Unless your admins write something that does.

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events