Atlassian
Atlassian Ongoing Bounty Program Summary Report
Pages
13
Time to read
9 mins
Publication
Language
English
Pages
13
Time to read
9 mins
Publication
Language
English
This report is a summary of the Ongoing Bounty Program conducted by Bugcrowd for Atlassian, covering the testing period from October 1, 2023, to December 31, 2023. The program aimed to identify security vulnerabilities across various Atlassian products by leveraging a crowd of security researchers. A total of 415 submissions were received from 246 unique researchers, resulting in 112 valid issues identified. The report outlines the methodology used, including the definition of the scope and targets for testing, which encompassed multiple Atlassian services such as Jira, Confluence, and Bitbucket. The findings are categorized by technical severity, detailing critical, high, medium, low, and informational vulnerabilities. Additionally, the report includes an appendix with metrics on submissions over time and a distribution overview of bug types. The document serves as a high-level overview of the security assessment conducted and the vulnerabilities discovered during the program.