Work at Atlassian? Claim it to respond to reviews as the verified owner.
Found a vulnerability?
If you would rather not deal with the vendor yourself, a BugRater analyst will submit it upstream on your behalf, with your explicit permission, and tell you what came back.
Ask BugRater to submit itPrivate. The report body is encrypted at rest; BugRater holds the key, so the analyst working it can read it. Every read is logged.
Reviews
0 publishedNo reviews yet.
Facts published by Bugcrowd on the program's own page, not reported by researchers, and not part of the BugRater grade. Last checked 19 Sep 2026.
Tools for teams, from startup to enterprise. Atlassian provides the tools to help every team unleash their full potential. Get Started (tl;dr version) Do not access, impact, destroy or otherwise negatively impact Atlassian customers, or customer data in anyway. Ensure that you use your @bugcrowdninja.com email address. Bounties are awarded differently per product (see below for more details on payouts). Ensure you understand the targets, scopes, exclusions, and rules in Scope & Rewards. Focus Areas Due to the collaborative nature of Atlassian products, we are not interested in vulnerabilities surrounding enumeration and information gathering (being able to work effectively as a team is the purpose of our products). Instead, we're more interested in traditional web application vulnerabilities, as well as other vulnerabilities that can have a direct impact to our products. Below is a list of some of the vulnerability classes that we are seeking reports for: Cross Instance Data Leakage/Access** Server-side Remote Code Execution (RCE) Server-Side Request Forgery (SSRF) Stored/Reflected Cross-site Scripting (XSS) Cross-site Request Forgery (CSRF) SQL Injection (SQLi) XML External Entity Attacks (XXE) Access Control Vulnerabilities (Insecure Direct Object Reference issues, etc) Path/Directory Traversal Issues Ensure you review the out of scope and exclusions list for further details. ** Cross Instance Data Leakage/Access refers to unauthorized data access between instances. Product Quick Links Jira and Confluence Cloud: Use the following naming convention for your cloud instance: bugbounty-test-<bugcrowd-name>.atlassian.net Once your cloud instance is set up, you can add additional cloud products at Atlassian Administration Bitbucket Cloud Data Center Products Jira Software Data Center Confluence Data Center Bitbucket Data Center Crowd Data Center Bamboo Data Center Other Products Crucible Fisheye Sourcetree We only accept vulnerabilities affecting the latest version of the product you are testing Mobile Products: Jira Cloud (iOS, Android) Confluence Cloud (iOS, Android) Jira Data Center (iOS, Android) Confluence Data Center (iOS, Android) Creating Your Instance Jira + Confluence Cloud To access the instance and start your testing (after you've read and understood the scope and exclusions listed below, of course) you can follow the below steps: Navigate to this page here Complete the verification flow When it is time to rename your instance, using the following format: bugbounty-test-<bugcrowd-name> Note that <bugcrowd-name> should be replaced with your own bugcrowd username Click "Agree" Once your instance has been completed that's it - you can test away! Additional Cloud Products Once your cloud instance is set up, you can add additional products via Atlassian Administration Go to the "Products" tab Click on "Add product" Select the cloud products you would like to add (e.g Jira Product Discovery, Jira Service Management, Jira Work Management, Statuspage) Bitbucket Cloud Navigate to https://bitbucket.org/ and select "Log In" Select "Sign Up" and create an account with your @bugcrowdninja.com email address. Start testing! All Atlassian Data Center Products To access the target and start your testing (after you've read and understood the scope and exclusions listed below, of course) you can follow the steps below: 1 - Go to Purchasing Licensing 2 - In the How can we help you dropdown, select Product trials. 3 - In the Choose a topic dropdown, select Trial a new product. 4 - At the bottom, select Need more help. 5 - In the Your Question field, type in your request. 6 - Submit your request and our support will help you get set up. Navigate to Data Center product link above Download the latest version of the product you want to test Install the product, with the trial license from the process above. Start testing To spin up a local Docker instance follow the steps located at: Confluence Jira Core Jira Software Jira Service Management Bitbucket Crowd Fisheye Bamboo Note: After the trial period expires you can generate another evaluation license and continue researching. Please remember to check that you are still on the latest version. Disclosure Request Guidance Submissions that meet the following requirements will be considered for disclosure upon request: The submission has been accepted The reported vulnerability has been fixed and released in production The submission does not regard a customer instance or a customer’s account
Scope
63 assets| Asset | Type | Eligibility | Max severity |
|---|---|---|---|
| *.atlastunnel.com | website | ✓ bounty | not set |
| *.loom.com | website | ✓ bounty | not set |
| Any associated *.atlassian.com or *.atl-paas.net domain that can be exploited DIRECTLY from the *.atlassian.net instance | other | ✓ bounty | not set |
| Any other *.atlassian.com or *.atl-paas.net domain that cannot be exploited directly from a *.atlassian.net instance | website | ✓ bounty | not set |
| Atlassian Admin (https://admin.atlassian.com/) | website | ✓ bounty | not set |
Show all 63 assets
| Asset | Type | Eligibility | Max severity |
|---|---|---|---|
| Atlassian Atlas | website | ✓ bounty | not set |
| Atlassian Compass | website | ✓ bounty | not set |
| Atlassian Guard Standard and Premium (https://admin.atlassian.com/atlassian-guard) | website | ✓ bounty | not set |
| Atlassian Identity (https://id.atlassian.com/login) | website | ✓ bounty | not set |
| Atlassian Marketplace (https://marketplace.atlassian.com) | website | ✓ bounty | not set |
| Atlassian MCP Server | other | ✓ bounty | not set |
| Atlassian Start (https://start.atlassian.com) | website | ✓ bounty | not set |
| Bamboo | website | ✓ bounty | not set |
| Bitbucket Cloud including Bitbucket Pipelines (https://bitbucket.org) | website | ✓ bounty | not set |
| Bitbucket Data Center | website | ✓ bounty | not set |
| Confluence Cloud (bugbounty-test-<bugcrowd-name>.atlassian.net/wiki) | website | ✓ bounty | not set |
| Confluence Cloud Mobile App for Android | android | ✓ bounty | not set |
| Confluence Cloud Mobile App for iOS | ios | ✓ bounty | not set |
| Confluence Cloud Premium (bugbounty-test-<bugcrowd-name>.atlassian.net/wiki) | website | ✓ bounty | not set |
| Confluence Companion App for macOS and Windows | other | ✓ bounty | not set |
| Confluence Data Center | other | ✓ bounty | not set |
| Confluence Data Center Mobile App for Android | android | ✓ bounty | not set |
| Confluence Data Center Mobile App for iOS | ios | ✓ bounty | not set |
| Crowd | website | ✓ bounty | not set |
| Crucible | website | ✓ bounty | not set |
| FishEye | website | ✓ bounty | not set |
| Forge Platform | other | ✓ bounty | not set |
| GraphQL API (bugbounty-test-<bugcrowd-name>.atlassian.net/gateway/api/graphql) | api | ✓ bounty | not set |
| https://www.npmjs.com/package/@forge/cli | other | ✓ bounty | not set |
| Jira Cloud Mobile App for Android | android | ✓ bounty | not set |
| Jira Cloud Mobile App for iOS | ios | ✓ bounty | not set |
| Jira Core Data Center | website | ✓ bounty | not set |
| Jira Data Center Mobile App for Android | android | ✓ bounty | not set |
| Jira Data Center Mobile App for iOS | ios | ✓ bounty | not set |
| Jira Product Discovery | website | ✓ bounty | not set |
| Jira Service Management Cloud (bugbounty-test-<bugcrowd-name>.atlassian.net) | website | ✓ bounty | not set |
| Jira Service Management Data Center | website | ✓ bounty | not set |
| Jira Software Cloud (bugbounty-test-<bugcrowd-name>.atlassian.net) | website | ✓ bounty | not set |
| Jira Software Data Center | website | ✓ bounty | not set |
| Jira Work Management Cloud formerly Jira Core (bugbounty-test-<bugcrowd-name>.atlassian.net) | website | ✓ bounty | not set |
| Loom Chrome Extension | other | ✓ bounty | not set |
| Loom Desktop App (macOS) | website | ✓ bounty | not set |
| Loom Desktop App (Windows) | website | ✓ bounty | not set |
| Loom for Android | android | ✓ bounty | not set |
| Loom for iOS | ios | ✓ bounty | not set |
| Other - (all other Atlassian targets) | other | ✓ bounty | not set |
| Other Rovo Dev | website | ✓ bounty | not set |
| Rovo | website | ✓ bounty | not set |
| Rovo Dev CLI | other | ✓ bounty | not set |
| Sourcetree for macOS and Windows (https://www.sourcetreeapp.com/) | other | ✓ bounty | not set |
| *.bitbucket.io | website | out | not set |
| Any customer instance. Do not test customer instances or affect customer data. Customer cloud instances may be in the form of <customer>.atlassian.net or <customer>.jira.com. Test only your own instances. | website | out | not set |
| Any internal or development services. | website | out | not set |
| Any repository that you are not an owner of - do not impact Atlassian customers in any way. | website | out | not set |
| bytebucket.org | website | out | not set |
| First and third party apps and plugins from the marketplace are excluded from this bounty but may be in scope for https://bugcrowd.com/atlassianapps | website | out | not set |
| HipChat (inc. HipChat Data Center, HipChat Desktop, HipChat Mobile) | other | out | not set |
| https://blog.bitbucket.org | website | out | not set |
| info.loom.com | website | out | not set |
| shop.atlassian.com | website | out | not set |
| Stride (inc. Stride Video, Stride Desktop, Stride Mobile) | other | out | not set |
| support.atlassian.com | website | out | not set |
| support.loom.com | website | out | not set |