Due to the collaborative nature of Atlassian products, we are not interested in vulnerabilities surrounding enumeration and information gathering (being able to work effectively as a team is the purpose of our products). Instead, we're more interested in traditional web application vulnerabilities, as well as other vulnerabilities that can have a direct impact to our products. Below is a list of some of the vulnerability classes that we are seeking reports for:
Ensure you review the out of scope and exclusions list for further details.
** Cross Instance Data Leakage/Access refers to unauthorized data access between instances.
Jira + Confluence Cloud
To access the instance and start your testing (after you've read and understood the scope and exclusions listed below, of course) you can follow the below steps:
Compass
Bitbucket
All Atlassian Server Products
To access the target and start your testing (after you've read and understood the scope and exclusions listed below, of course) you can follow the below steps:
Note: After the trial period expires you can generate another evaluation license and continue researching. Please remember to check that you are still on the latest version.
This program follows Bugcrowd’s standard disclosure terms.
For any testing issues (such as broken credentials, inaccessible application, or Bugcrowd Ninja email problems), please email support@bugcrowd.com. We will address your issue as soon as possible.
This program does not offer financial or point-based rewards for P5 — Informational findings. Learn more about Bugcrowd’s VRT.
Scope Type | Scope Name |
---|---|
android_application | Confluence Cloud Mobile App for Android |
android_application | Jira Cloud Mobile App for Android |
android_application | Confluence Server Mobile App for Android |
android_application | Jira Server Mobile App for Android |
ios_application | Confluence Cloud Mobile App for iOS |
ios_application | Jira Cloud Mobile App for iOS |
ios_application | Confluence Server Mobile App for iOS |
ios_application | Jira Server Mobile App for iOS |
undefined | Jira Core Server |
undefined | Jira Software Server |
undefined | Confluence Server |
undefined | Bitbucket Server |
undefined | Bamboo |
undefined | Crowd |
undefined | FishEye |
undefined | Crucible |
undefined | Other - (all other Atlassian targets) |
undefined | Any associated .atlassian.com or .atl-paas.net domain that can be exploited DIRECTLY from the *.atlassian.net instance |
undefined | Jira Service Management Server |
undefined | Any other .atlassian.com or .atl-paas.net domain that cannot be exploited directly from a *.atlassian.net instance |
undefined | Confluence Companion App for macOS and Windows |
undefined | Atlassian Compass |
undefined | Atlassian Team Central |
web_application | Confluence Cloud (bugbounty-test-.atlassian.net/wiki) |
web_application | *.atlastunnel.com |
web_application | Atlassian Access (https://admin.atlassian.com/atlassian-access) |
web_application | Atlassian Admin (https://admin.atlassian.com/) |
web_application | Atlassian Identity (https://id.atlassian.com/login) |
web_application | Atlassian Start (https://start.atlassian.com) |
web_application | Bitbucket Cloud including Bitbucket Pipelines (https://bitbucket.org) |
web_application | Confluence Cloud Premium (bugbounty-test-.atlassian.net/wiki) |
web_application | Jira Service Management Cloud (bugbounty-test-.atlassian.net) |
web_application | Jira Software Cloud (bugbounty-test-.atlassian.net) |
web_application | Jira Work Management Cloud formerly Jira Core (bugbounty-test-.atlassian.net) |
web_application | Atlassian Marketplace (https://marketplace.atlassian.com) |
web_application | Sourcetree for macOS and Windows (https://www.sourcetreeapp.com/) |
Scope Type | Scope Name |
---|---|
undefined | Any repository that you are not an owner of - do not impact Atlassian customers in any way. |
undefined | Any internal or development services. |
undefined | HipChat (inc. HipChat Data Center, HipChat Desktop, HipChat Mobile) |
undefined | Stride (inc. Stride Video, Stride Desktop, Stride Mobile) |
undefined | Jira Align (formerly AgileCraft) and any Related Assets |
web_application | *.bitbucket.io |
web_application | https://blog.bitbucket.org |
web_application | bytebucket.org |
web_application | First and third party apps and plugins from the marketplace are excluded from this bounty but may be in scope for https://bugcrowd.com/atlassianapps |
On this program you get up to 10000 $ for the most critical vulnerability.
FireBounty © 2015-2024