Early access: the directory is still filling out, and every rating here is a reported experience.
NR Unrated
Atlassian
Atlassian Bugcrowd $100–$12,000
3 more reviews needed for a grade
Write a review Claim this company profile

Work at Atlassian? Claim it to respond to reviews as the verified owner.

Found a vulnerability?

If you would rather not deal with the vendor yourself, a BugRater analyst will submit it upstream on your behalf, with your explicit permission, and tell you what came back.

Ask BugRater to submit it

Private. The report body is encrypted at rest; BugRater holds the key, so the analyst working it can read it. Every read is logged.

Reviews

0 published

No reviews yet.

Be the first to review

Program profile Bugcrowd · imported

Facts published by Bugcrowd on the program's own page, not reported by researchers, and not part of the BugRater grade. Last checked 19 Sep 2026.

Tools for teams, from startup to enterprise. Atlassian provides the tools to help every team unleash their full potential. Get Started (tl;dr version) Do not access, impact, destroy or otherwise negatively impact Atlassian customers, or customer data in anyway. Ensure that you use your @bugcrowdninja.com email address. Bounties are awarded differently per product (see below for more details on payouts). Ensure you understand the targets, scopes, exclusions, and rules in Scope & Rewards. Focus Areas Due to the collaborative nature of Atlassian products, we are not interested in vulnerabilities surrounding enumeration and information gathering (being able to work effectively as a team is the purpose of our products). Instead, we're more interested in traditional web application vulnerabilities, as well as other vulnerabilities that can have a direct impact to our products. Below is a list of some of the vulnerability classes that we are seeking reports for: Cross Instance Data Leakage/Access** Server-side Remote Code Execution (RCE) Server-Side Request Forgery (SSRF) Stored/Reflected Cross-site Scripting (XSS) Cross-site Request Forgery (CSRF) SQL Injection (SQLi) XML External Entity Attacks (XXE) Access Control Vulnerabilities (Insecure Direct Object Reference issues, etc) Path/Directory Traversal Issues Ensure you review the out of scope and exclusions list for further details. ** Cross Instance Data Leakage/Access refers to unauthorized data access between instances. Product Quick Links Jira and Confluence Cloud:  Use the following naming convention for your cloud instance: bugbounty-test-<bugcrowd-name>.atlassian.net Once your cloud instance is set up, you can add additional cloud products at Atlassian Administration Bitbucket Cloud Data Center Products Jira Software Data Center Confluence Data Center Bitbucket Data Center Crowd Data Center Bamboo Data Center Other Products Crucible Fisheye Sourcetree We only accept vulnerabilities affecting the latest version of the product you are testing Mobile Products: Jira Cloud (iOS, Android) Confluence Cloud (iOS, Android) Jira Data Center (iOS, Android) Confluence Data Center (iOS, Android) Creating Your Instance Jira + Confluence Cloud To access the instance and start your testing (after you've read and understood the scope and exclusions listed below, of course) you can follow the below steps: Navigate to this page here Complete the verification flow When it is time to rename your instance, using the following format: bugbounty-test-<bugcrowd-name> Note that <bugcrowd-name> should be replaced with your own bugcrowd username Click "Agree" Once your instance has been completed that's it - you can test away! Additional Cloud Products Once your cloud instance is set up, you can add additional products via Atlassian Administration Go to the "Products" tab Click on "Add product" Select the cloud products you would like to add (e.g Jira Product Discovery, Jira Service Management, Jira Work Management, Statuspage) Bitbucket Cloud Navigate to https://bitbucket.org/ and select "Log In" Select "Sign Up" and create an account with your @bugcrowdninja.com email address. Start testing! All Atlassian Data Center Products To access the target and start your testing (after you've read and understood the scope and exclusions listed below, of course) you can follow the steps below: 1 - Go to Purchasing Licensing 2 - In the How can we help you dropdown, select Product trials. 3 - In the Choose a topic dropdown, select Trial a new product. 4 - At the bottom, select Need more help. 5 - In the Your Question field, type in your request. 6 - Submit your request and our support will help you get set up. Navigate to Data Center product link above Download the latest version of the product you want to test Install the product, with the trial license from the process above. Start testing To spin up a local Docker instance follow the steps located at: Confluence Jira Core Jira Software Jira Service Management Bitbucket Crowd Fisheye Bamboo Note: After the trial period expires you can generate another evaluation license and continue researching. Please remember to check that you are still on the latest version. Disclosure Request Guidance Submissions that meet the following requirements will be considered for disclosure upon request: The submission has been accepted The reported vulnerability has been fixed and released in production The submission does not regard a customer instance or a customer’s account

Currency
USD
Submissions
Open
Scope entries
63 Bugcrowd’s count

Scope

63 assets
AssetTypeEligibilityMax severity
*.atlastunnel.com website ✓ bounty not set
*.loom.com website ✓ bounty not set
Any associated *.atlassian.com or *.atl-paas.net domain that can be exploited DIRECTLY from the *.atlassian.net instance other ✓ bounty not set
Any other *.atlassian.com or *.atl-paas.net domain that cannot be exploited directly from a *.atlassian.net instance website ✓ bounty not set
Atlassian Admin (https://admin.atlassian.com/) website ✓ bounty not set
Show all 63 assets
AssetTypeEligibilityMax severity
Atlassian Atlas website ✓ bounty not set
Atlassian Compass website ✓ bounty not set
Atlassian Guard Standard and Premium (https://admin.atlassian.com/atlassian-guard) website ✓ bounty not set
Atlassian Identity (https://id.atlassian.com/login) website ✓ bounty not set
Atlassian Marketplace (https://marketplace.atlassian.com) website ✓ bounty not set
Atlassian MCP Server other ✓ bounty not set
Atlassian Start (https://start.atlassian.com) website ✓ bounty not set
Bamboo website ✓ bounty not set
Bitbucket Cloud including Bitbucket Pipelines (https://bitbucket.org) website ✓ bounty not set
Bitbucket Data Center website ✓ bounty not set
Confluence Cloud (bugbounty-test-<bugcrowd-name>.atlassian.net/wiki) website ✓ bounty not set
Confluence Cloud Mobile App for Android android ✓ bounty not set
Confluence Cloud Mobile App for iOS ios ✓ bounty not set
Confluence Cloud Premium (bugbounty-test-<bugcrowd-name>.atlassian.net/wiki) website ✓ bounty not set
Confluence Companion App for macOS and Windows other ✓ bounty not set
Confluence Data Center other ✓ bounty not set
Confluence Data Center Mobile App for Android android ✓ bounty not set
Confluence Data Center Mobile App for iOS ios ✓ bounty not set
Crowd website ✓ bounty not set
Crucible website ✓ bounty not set
FishEye website ✓ bounty not set
Forge Platform other ✓ bounty not set
GraphQL API (bugbounty-test-<bugcrowd-name>.atlassian.net/gateway/api/graphql) api ✓ bounty not set
https://www.npmjs.com/package/@forge/cli other ✓ bounty not set
Jira Cloud Mobile App for Android android ✓ bounty not set
Jira Cloud Mobile App for iOS ios ✓ bounty not set
Jira Core Data Center website ✓ bounty not set
Jira Data Center Mobile App for Android android ✓ bounty not set
Jira Data Center Mobile App for iOS ios ✓ bounty not set
Jira Product Discovery website ✓ bounty not set
Jira Service Management Cloud (bugbounty-test-<bugcrowd-name>.atlassian.net) website ✓ bounty not set
Jira Service Management Data Center website ✓ bounty not set
Jira Software Cloud (bugbounty-test-<bugcrowd-name>.atlassian.net) website ✓ bounty not set
Jira Software Data Center website ✓ bounty not set
Jira Work Management Cloud formerly Jira Core (bugbounty-test-<bugcrowd-name>.atlassian.net) website ✓ bounty not set
Loom Chrome Extension other ✓ bounty not set
Loom Desktop App (macOS) website ✓ bounty not set
Loom Desktop App (Windows) website ✓ bounty not set
Loom for Android android ✓ bounty not set
Loom for iOS ios ✓ bounty not set
Other - (all other Atlassian targets) other ✓ bounty not set
Other Rovo Dev website ✓ bounty not set
Rovo website ✓ bounty not set
Rovo Dev CLI other ✓ bounty not set
Sourcetree for macOS and Windows (https://www.sourcetreeapp.com/) other ✓ bounty not set
*.bitbucket.io website out not set
Any customer instance. Do not test customer instances or affect customer data. Customer cloud instances may be in the form of <customer>.atlassian.net or <customer>.jira.com. Test only your own instances. website out not set
Any internal or development services. website out not set
Any repository that you are not an owner of - do not impact Atlassian customers in any way. website out not set
bytebucket.org website out not set
First and third party apps and plugins from the marketplace are excluded from this bounty but may be in scope for https://bugcrowd.com/atlassianapps website out not set
HipChat (inc. HipChat Data Center, HipChat Desktop, HipChat Mobile) other out not set
https://blog.bitbucket.org website out not set
info.loom.com website out not set
shop.atlassian.com website out not set
Stride (inc. Stride Video, Stride Desktop, Stride Mobile) other out not set
support.atlassian.com website out not set
support.loom.com website out not set