-
Bug
-
Resolution: Fixed
-
Low (View bug fix roadmap)
-
None
-
3
-
Severity 3 - Minor
-
3
-
The option values for this custom field type are already html escaped in Jira Cloud due to security concerns. This issue is to track switching the default value for the "Enable HTML in custom field descriptions and list item values" setting to be "OFF" by default.
- derived from
-
JRASERVER-38827 Putting HTML tags into multi-select options interferes with filtering
-
- Closed
-
- is related to
-
JRACLOUD-66392 Remove text from Select List Custom Field configuration UI suggesting HTML markup is supported within option values
-
- Closed
-
-
JRASERVER-61876 Custom field is not rendering HTML content in JIRA 7 and above
-
- Gathering Impact
-
-
JRASERVER-70859 Disallow HTML in custom field descriptions and list item values by default
- Closed
- has action
-
RM-11291 Failed to load
- mentioned in
-
Page Loading...
-
Page Loading...
-
Page Loading...
-
Page Loading...
-
Page Loading...
-
Page Loading...
-
Page Loading...
-
Page Loading...
-
Page Loading...
I'm just glad that after upgrading I was able to find this and find that there is an option in general settings.
In the meantime that was a lot of curse words because if you had a rogue Jira admin I am pretty sure they would not bother with some field configs or custom fields, as there are plenty other better ways to be a terrorist.