Bugcrowd report clarification

Philip Choudhury May 26, 2020

Hello Team,

Due to a compliance requirement, we had to share Pen Test report of Jira (Atlassian Bugcrowd 2019 Q4).

Now we need a statement from you stating Vulnerabilities mentioned in this specific report (Link below) were already addressed by the time report made available publicly.

https://www.atlassian.com/br/dam/jcr:161357c4-7380-450f-b8a6-0a4cb14af625/Atlassian_Bugcrowd_Report-2020-01.pdf

P.S. Raised a ticket (JST-575038) with tech support team and have been redirected here.

1 comment

Comment

Log in or Sign up to comment
Philip Choudhury May 29, 2020

Team, any update on this.

Bill Marriott
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
June 2, 2020

Hi @ph - as stated on https://www.atlassian.com/trust/security/security-testing 

"Any security vulnerabilities identified in the reports are tracked in our internal Jira as they come through the Bug Bounty intake process and any findings from the Bug Bounty will be triaged and remediated according to our Public Security Vulnerability SLA."

Any issue from the January report is now over 6 months old, and the longest SLA is 8 weeks (Medium severity), which means they are fixed now. In fact, all of the items from the April Report (currently posted) are all now past the SLA dates and are fixed. 

Hope that helps.

-bill marriott

Atlassian Trust & Security

Like Philip Choudhury likes this
Philip Choudhury June 3, 2020

Thank you Bill, your reply addressed the requirement.

TAGS
AUG Leaders

Atlassian Community Events