Hello,
We would like to use the HTML or HTML include macro for our confluence instance
https://confluence.atlassian.com/conf74/html-macro-1003128855.html
https://confluence.atlassian.com/conf74/html-include-macro-1003128854.html
Both of these macro pose the risk of XSS vulnerability. We are using version 7.4.1 . Is there a way to use these macros and avoid the risk of XSS. I read some older articles about disabling JS. Is this available in Server version 7.4.1 ?
Our use case is to be able to include Google Docs in the confluence. So if there is a suggestion for another macro or FREE solution to achieve inclusion of Google Docs without the use of HTML macro / risk of XSS, would be open to that suggestion as well.
Hi @Umang
Both macros can make your environment vulnerable, even on the latest version of Confluence.
If security is must on your environment, it would be better to rely on a Supported App available on Atlassian Marketplace.
There are at least 3 options that may fit your use case: https://marketplace.atlassian.com/search?hosting=server&moreFilters=vendorSupported&product=confluence&query=google%20drive
Kind regards,
Thiago Masutti
Thank you for the response. So is there no way to disable Javascript or script encoding or escaping which would stop execution of Javascript when using either of the HTML macros?
Alternatively, is there a way to enable the macros for specific users only ?
Thank you for the link to the marketplace apps. However looks like they are all paid apps, which may not be an option for us right now.
Regards
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Online forums and learning are now in one easy-to-use experience.
By continuing, you accept the updated Community Terms of Use and acknowledge the Privacy Policy. Your public name, photo, and achievements may be publicly visible and available in search engines.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.