-
Type:
Suggestion
-
Resolution: Unresolved
-
None
-
Component/s: Issue - Comments, Issue - Fields, REST API, Security
-
None
-
1
Problem
Jira allows special characters insertion on different default and custom fields ,this allows to launch attacks such as SQL injection, XSS.
Suggested Solution
- Implement a screen to manage and allowlist input characters
Why This Is Important
As much as it is complex and technically difficult to identify the usage context, filtering characters for certain inputs can offer a great deal of security