Reporting a security issue

If you believe you have found a security problem in a Capable app, tell us directly rather than filing it as a support ticket or posting it publicly.

We would rather hear about a false alarm than miss a real one.


#How to report

  • Contact us through the Capable service desk, marking the request as a security issue.

  • Include what you found, how to reproduce it, and what you think the impact is.

  • Tell us if you have shared it anywhere else, and give us a chance to fix it before you do.


#What happens next

Stage

What we do

Acknowledgement

We confirm we have it, and who is looking at it

Assessment

We reproduce it and work out the real impact

Fix

We ship a fix, and tell you when it is out

Disclosure

If customers were affected, it gets an incident report on this space


#A few things worth knowing

  • A vulnerability that affected customers gets a public incident report, the same as an outage.

  • We will tell you if something you reported turns out to be intended behaviour, and why.

  • Reports about the Atlassian platform itself are better raised with Atlassian, but tell us too and we will help.



Tell us first. We would rather know.