zerotier.atlassian.net
External Program
Submit bugs directly to this organization
External Program
Submit bugs directly to this organization
If you believe you have found a security issue that meets Atlassian’s [#definition-of-vulnerability](definition of a vulnerability), please submit the report to our security team via one of the methods below.
We are unable to respond to bulk reports generated by automated scanners. If you identify issues using an automated scanner, it is recommended that you have a security practitioner review the issues and ensure that the findings are valid before submitting a vulnerability report to Atlassian.
If you are a customer:
Submit a ticket to [https://support.atlassian.com/contact/](our support team) If you are a security researcher:
Submit a report through our [#bug-bounty-program](bug bounty program); or
Submit a Security Concern ticket to [https://support.atlassian.com/contact/](our support team) Only vulnerabilities submitted through our [#bug-bounty-program](bug bounty program) are eligible to receive a bounty payment.
Please include the following information in your report:
Atlassian considers a security vulnerability to be a weakness in one of our products or infrastructure that could allow an attacker to impact the confidentiality, integrity, or availability of the product or infrastructure.
We do not consider the following types of findings to be security vulnerabilities:
At Atlassian, one of our values is Open Company, No Bullshit, we believe that vulnerability disclosure is a part of that value. We hold ourselves to the security bug fix service level objectives, found /trust/security/bug-fix-policy, and will accept disclosure requests in the bug bounty program after the issue has been fixed and released in production. However, if the report contains any information regarding a customer instance or data the request will be rejected. We ask that you give us reasonable notice and wait until the [/trust/security/bug-fix-policy](associated SLO) has passed. Please note we do not provide rewards for submission via email. If you are looking for our Bug Bounty program, please go https://bugcrowd.com/atlassian.
When conducting vulnerability research according to this policy, we consider this research to be:
Atlassian operates a public bug bounty program for our products via our partner, Bugcrowd. Security researchers can receive cash payments in exchange for a qualifying vulnerability report submitted to Atlassian via our bounty programs.
Atlassian makes it a priority to resolve any security vulnerabilities in our products within the timeframes identified in our [/trust/security/bug-fix-policy](Security Bugfix Policy). Atlassian follows coordinated vulnerability disclosure and requests, to protect our customers, that anyone reporting a vulnerability to us does the same.
[/trust/security/vulnerability-management](Our Approach to Vulnerability Management)
[/trust/security/security-testing](Our Approach to External Security Testing)