52235 policies in database
Link to program      
2018-03-22
2020-01-23
Atlassian logo
Thank
Gift
HOF
Reward

Reward

200 $ 

Atlassian

Tools for teams, from startup to enterprise. Atlassian provides the tools to help every team unleash their full potential.

Get Started (tl;dr version)

  • Do not access, impact, destroy or otherwise negatively impact Atlassian customers, or customer data in anyway.
  • Ensure that you use your @bugcrowdninja.com email address.
  • Bounties are awarded differently per product (see below for more details on payouts).
  • Ensure you understand the targets, scopes, exclusions, and rules in Scope & Rewards.

Focus Areas

Due to the collaborative nature of Atlassian products, we are not interested in vulnerabilities surrounding enumeration and information gathering (being able to work effectively as a team is the purpose of our products). Instead, we're more interested in traditional web application vulnerabilities, as well as other vulnerabilities that can have a direct impact to our products. Below is a list of some of the vulnerability classes that we are seeking reports for:

  • Cross Instance Data Leakage/Access**
  • Server-side Remote Code Execution (RCE)
  • Server-Side Request Forgery (SSRF)
  • Stored/Reflected Cross-site Scripting (XSS)
  • Cross-site Request Forgery (CSRF)
  • SQL Injection (SQLi)
  • XML External Entity Attacks (XXE)
  • Access Control Vulnerabilities (Insecure Direct Object Reference issues, etc)
  • Path/Directory Traversal Issues

Ensure you review the out of scope and exclusions list for further details.

** Cross Instance Data Leakage/Access refers to unauthorized data access between instances.

Quick Links

Creating Your Instance

Jira + Confluence Cloud
To access the instance and start your testing (after you've read and understood the scope and exclusions listed below, of course) you can follow the below steps:

  • Navigate to the checkout page here
  • Click "Next"
  • Complete the form, using the following format: bugbounty-test-<bugcrowd-name> Note that <bugcrowd-name> should be replaced with your own bugcrowd username
  • Click "Start now"
  • Once your instance has been completed that's it - you can test away.

Compass

  1. Navigate to https://www.atlassian.com/software/compass
  2. Provide your @bugcrowdninja.com email address
  3. We will send you a survey
  4. In the survey, note that you are a bugcrowd security researcher
  5. Wait for another email to get access and start testing

Bitbucket

  1. Navigate to https://bitbucket.org/ and select "Log In"
  2. Select "Sign Up" and create an account with your @bugcrowdninja.com email address.
  3. Start testing

All Atlassian Server Products
To access the target and start your testing (after you've read and understood the scope and exclusions listed below, of course) you can follow the below steps:

  1. Navigate to www.atlassian.com
  2. Download the server version of the product you want to test,
  3. Install the product,
  4. (if required) Generate a trial license for the product,
  5. Start testing

Note: After the trial period expires you can generate another evaluation license and continue researching. Please remember to check that you are still on the latest version.

Scope and rewards

Program rules

This program follows Bugcrowd’s standard disclosure terms.

For any testing issues (such as broken credentials, inaccessible application, or Bugcrowd Ninja email problems), please email support@bugcrowd.com. We will address your issue as soon as possible.

This program does not offer financial or point-based rewards for P5 — Informational findings. Learn more about Bugcrowd’s VRT.

In Scope

Scope Type Scope Name
android_application

Confluence Cloud Mobile App for Android

android_application

Jira Cloud Mobile App for Android

android_application

Confluence Server Mobile App for Android

android_application

Jira Server Mobile App for Android

ios_application

Confluence Cloud Mobile App for iOS

ios_application

Jira Cloud Mobile App for iOS

ios_application

Confluence Server Mobile App for iOS

ios_application

Jira Server Mobile App for iOS

undefined

Jira Core Server

undefined

Jira Software Server

undefined

Confluence Server

undefined

Bitbucket Server

undefined

Bamboo

undefined

Crowd

undefined

FishEye

undefined

Crucible

undefined

Other - (all other Atlassian targets)

undefined

Any associated .atlassian.com or .atl-paas.net domain that can be exploited DIRECTLY from the *.atlassian.net instance

undefined

Jira Service Management Server

undefined

Any other .atlassian.com or .atl-paas.net domain that cannot be exploited directly from a *.atlassian.net instance

undefined

Confluence Companion App for macOS and Windows

undefined

Atlassian Compass

undefined

Atlassian Team Central

web_application

Confluence Cloud (bugbounty-test-.atlassian.net/wiki)

web_application

*.atlastunnel.com

web_application

Atlassian Access (https://admin.atlassian.com/atlassian-access)

web_application

Atlassian Admin (https://admin.atlassian.com/)

web_application

Atlassian Identity (https://id.atlassian.com/login)

web_application

Atlassian Start (https://start.atlassian.com)

web_application

Bitbucket Cloud including Bitbucket Pipelines (https://bitbucket.org)

web_application

Confluence Cloud Premium (bugbounty-test-.atlassian.net/wiki)

web_application

Jira Service Management Cloud (bugbounty-test-.atlassian.net)

web_application

Jira Software Cloud (bugbounty-test-.atlassian.net)

web_application

Jira Work Management Cloud formerly Jira Core (bugbounty-test-.atlassian.net)

web_application

Atlassian Marketplace (https://marketplace.atlassian.com)

web_application

Sourcetree for macOS and Windows (https://www.sourcetreeapp.com/)

Out of Scope

Scope Type Scope Name
undefined

Any repository that you are not an owner of - do not impact Atlassian customers in any way.

undefined

Any internal or development services.

undefined

HipChat (inc. HipChat Data Center, HipChat Desktop, HipChat Mobile)

undefined

Stride (inc. Stride Video, Stride Desktop, Stride Mobile)

undefined

Jira Align (formerly AgileCraft) and any Related Assets

web_application

*.bitbucket.io

web_application

https://blog.bitbucket.org

web_application

bytebucket.org

web_application

First and third party apps and plugins from the marketplace are excluded from this bounty but may be in scope for https://bugcrowd.com/atlassianapps


On this program you get up to 10000 $ for the most critical vulnerability.

FireBounty © 2015-2024

Legal notices | Privacy policy