Reporting a security issue
If you believe you have found a security problem in a Capable app, tell us directly rather than filing it as a support ticket or posting it publicly.
We would rather hear about a false alarm than miss a real one.
#How to report
Contact us through the Capable service desk, marking the request as a security issue.
Include what you found, how to reproduce it, and what you think the impact is.
Tell us if you have shared it anywhere else, and give us a chance to fix it before you do.
#What happens next
Stage | What we do |
|---|---|
Acknowledgement | We confirm we have it, and who is looking at it |
Assessment | We reproduce it and work out the real impact |
Fix | We ship a fix, and tell you when it is out |
Disclosure | If customers were affected, it gets an incident report on this space |
Please do not test against another customer's site. Use your own instance or a free developer instance. Testing against somebody else's data is not research.
#A few things worth knowing
A vulnerability that affected customers gets a public incident report, the same as an outage.
We will tell you if something you reported turns out to be intended behaviour, and why.
Reports about the Atlassian platform itself are better raised with Atlassian, but tell us too and we will help.
#Related
Tell us first. We would rather know.
