Create
cancel
Showing results for 
Search instead for 
Did you mean: 
Sign up Log in
Celebration

Earn badges and make progress

You're on your way to the next level! Join the Kudos program to earn points and save your progress.

Deleted user Avatar
Deleted user

Level 1: Seed

25 / 150 points

Next: Root

Avatar

1 badge earned

Collect

Participate in fun challenges

Challenges come and go, but your rewards stay with you. Do more to earn more!

Challenges
Coins

Gift kudos to your peers

What goes around comes around! Share the love by gifting kudos to your peers.

Recognition
Ribbon

Rise up in the ranks

Keep earning points to reach the top of the leaderboard. It resets every quarter so you always have a chance!

Leaderboard

Come for the products,
stay for the community

The Atlassian Community can help you and your team get more value out of Atlassian products and practices.

Atlassian Community about banner
4,460,447
Community Members
 
Community Events
176
Community Groups

Bugcrowd report clarification

Hello Team,

Due to a compliance requirement, we had to share Pen Test report of Jira (Atlassian Bugcrowd 2019 Q4).

Now we need a statement from you stating Vulnerabilities mentioned in this specific report (Link below) were already addressed by the time report made available publicly.

https://www.atlassian.com/br/dam/jcr:161357c4-7380-450f-b8a6-0a4cb14af625/Atlassian_Bugcrowd_Report-2020-01.pdf

P.S. Raised a ticket (JST-575038) with tech support team and have been redirected here.

1 comment

Team, any update on this.

Hi @ph - as stated on https://www.atlassian.com/trust/security/security-testing 

"Any security vulnerabilities identified in the reports are tracked in our internal Jira as they come through the Bug Bounty intake process and any findings from the Bug Bounty will be triaged and remediated according to our Public Security Vulnerability SLA."

Any issue from the January report is now over 6 months old, and the longest SLA is 8 weeks (Medium severity), which means they are fixed now. In fact, all of the items from the April Report (currently posted) are all now past the SLA dates and are fixed. 

Hope that helps.

-bill marriott

Atlassian Trust & Security

Like Philip Choudhury likes this

Thank you Bill, your reply addressed the requirement.

Comment

Log in or Sign up to comment
TAGS

Atlassian Community Events