{"id":"b324d66b-aa06-497b-ae39-5ea7c4442c27","engagementId":"442d780f-fccd-4501-a759-684811f12797","data":{"brief":{"id":"d5697397-11e1-4174-8373-6c20d20c84c5","name":"Redmoon","tagline":"Redmoon's bug bounty program","description":"\u003cp\u003e\u003cstrong\u003eThis bounty is part of the Atlassian Marketplace Bounty Program\u003c/strong\u003e\u003c/p\u003e\n\n\u003cp\u003eRedmoon Software is a Jira add-on development company.  We pride ourselves in quality, user-friendliness and good responsive service.\u003c/p\u003e\n\n\u003ch4\u003eGet Started (tl;dr version)\u003c/h4\u003e\n\n\u003cp\u003e• Do not access, impact, destroy or otherwise negatively impact Redmoon Software or Atlassian customers, or customer data in any way.\u003cbr\u003e\n• Ensure that you use your \u003cem\u003e@bugcrowdninja.com\u003c/em\u003e email address.\u003cbr\u003e\n• Ensure you understand the targets, scopes, exclusions, and rules below – no public disclosure without prior consent.\u003cbr\u003e\n• The plugin located at the URL is in scope but the Marketplace page itself is \u003cem\u003eNOT\u003c/em\u003e.\u003c/p\u003e\n\n\u003ch4\u003eQuick Links\u003c/h4\u003e\n\n\u003cul\u003e\n\u003cli\u003e\n\u003ca href=\"https://marketplace.atlassian.com/apps/1211639/comment-history-for-jira?hosting=cloud\u0026amp;tab=overview\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eComment History for Jira Cloud\u003c/a\u003e (Cloud version only) \u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://marketplace.atlassian.com/apps/1213649/custom-fields-for-jira-cloud?hosting=cloud\u0026amp;tab=overview\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eCustom Fields for Jira\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\n\u003ca href=\"https://marketplace.atlassian.com/apps/1211880/document-vault-secure-attachments-in-jira\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eDocument Vault for Jira cloud\u003c/a\u003e (Cloud version only) \u003c/li\u003e\n\u003cli\u003e\n\u003ca href=\"https://marketplace.atlassian.com/apps/1214056/sub-task-manager-for-jira?hosting=cloud\u0026amp;tab=overview\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eSub Task Manager for Jira\u003c/a\u003e (Cloud version only) \u003c/li\u003e\n\u003cli\u003e\n\u003ca href=\"https://marketplace.atlassian.com/apps/1213851/watch-it-for-jira-cloud?hosting=cloud\u0026amp;tab=overview\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eWatch It for Jira\u003c/a\u003e (Cloud version only) \u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eFocus Areas\u003c/h3\u003e\n\n\u003cp\u003eBelow is a list of some of the vulnerability classes that we are seeking reports for:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eCross Instance Data Leakage/Access**\u003c/li\u003e\n\u003cli\u003eServer-side Remote Code Execution (RCE)\u003c/li\u003e\n\u003cli\u003eServer-Side Request Forgery (SSRF)\u003c/li\u003e\n\u003cli\u003eStored/Reflected Cross-site Scripting (XSS)\u003c/li\u003e\n\u003cli\u003eCross-site Request Forgery (CSRF)\u003c/li\u003e\n\u003cli\u003eSQL Injection (SQLi)\u003c/li\u003e\n\u003cli\u003eAccess Control Vulnerabilities (Insecure Direct Object Reference issues, etc)\u003c/li\u003e\n\u003cli\u003ePath/Directory Traversal Issues\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eEnsure you review the out of scope and exclusions list for further details.\u003c/em\u003e\u003c/p\u003e\n\n\u003cp\u003e** Cross Instance Data Leakage/Access refers to unauthorized data access between instances.\u003c/p\u003e\n\n\u003ch2\u003eRatings/Rewards:\u003c/h2\u003e\n\n\u003cp\u003e\u003cem\u003eFor the initial prioritization/rating of findings, this program will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority. Please see below for deviations.\u003c/em\u003e\u003c/p\u003e","industryTagId":"d7a636ff-c862-4101-a74f-f556036a5772","targetsOverview":"\u003ch3\u003eRules, Exclusions, and Scopes\u003c/h3\u003e\n\n\u003cp\u003eAny domain/property of Redmoon Software not listed in the targets section is strictly out of scope (for more information please see the out of scope and exclusions sections below). \u003cstrong\u003eResearchers should use the \"bugbounty-test-\u0026lt;bugcrowd-name\u0026gt;.atlassian.net\" namespace\u003c/strong\u003e provided in the instructions below. Please do not create additional instances outside of this namespace for testing.\u003c/p\u003e\n\n\u003ch2\u003eOut-of-Scope\u003c/h2\u003e\n\n\u003cp\u003eAnything not declared as a target or in scope above should be considered out of scope. However to help the following are considered out of scope.\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eOut of scope: anything not explicitly declared in scope.\u003c/li\u003e\n\u003cli\u003e\u0026amp;=*.atlassian.com domain.\u003c/li\u003e\n\u003cli\u003eBlind XSS returning unauthorized data (e.g. screenshots, cookies); use least invasive tests (e.g. 1x1 image, nonexistent page).\u003c/li\u003e\n\u003cli\u003eInjecting public forms without removable payloads; check with support@bugcrowd first.\u003c/li\u003e\n\u003cli\u003ePivoting, post-exploitation, or leveraging findings to discover further issues.\u003c/li\u003e\n\u003cli\u003eRedmoon Software websites.\u003c/li\u003e\n\u003cli\u003eCustomer cloud instances and data.\u003c/li\u003e\n\u003cli\u003eRepositories you do not own.\u003c/li\u003e\n\u003cli\u003eProduct versions older than the latest release.\u003c/li\u003e\n\u003cli\u003eInternal or development services.\u003c/li\u003e\n\u003cli\u003eExpired tokens for page loads.\u003c/li\u003e\n\u003cli\u003eGranularity mismatch: App project admins gaining global project updates, bypassing Jira's per-project constraints.\u003c/li\u003e\n\u003cli\u003eExploits via Watch It tracker Payload field or timed tracker pages.\u003c/li\u003e\n\u003cli\u003eUnauthenticated submits/web triggers for Comment History and Document Vault (known issue).\u003c/li\u003e\n\u003cli\u003eComment History (known/in-progress): Stored XSS/HTML injection via rendering; unsafe CSP (unsafe-inline/eval); SSRF via resolvers; verbose logging/error disclosure; missing input validation on IDs; npm dependencies CVEs; missing rate limiting on resolvers; unbounded pagination.\u003c/li\u003e\n\u003cli\u003eSTM,Watch It,Custom Fields - Responses from /_ah/api/ endpoints return internal token fields (\"forgeInvocationToken\",\"forgeSiteUrl\",\"forgeApiBaseUrl\") to the browser, exposing the app's Forge OAuth token. Disclosure on any endpoint, and anything done with the leaked token (Jira access as the app account), are out of scope.\n### STM\u003c/li\u003e\n\u003cli\u003eAccessing complete template list (all users require access for bulk create/JQL).\u003c/li\u003e\n\u003cli\u003eBulk Create/update pages executing calls for unauthorized users.\u003c/li\u003e\n\u003cli\u003ePages visible to users lacking access.\u003c/li\u003e\n\u003cli\u003ePOST /forgeWebhook authenticates only by comparing the X-Forge-Source header to \"true\" and never verifies the Forge invocation token as a signed JWT (no signature/issuer/audience/expiry; falls back to any Authorization: Bearer). Cross-tenant issue manipulation, forged executor-pipeline runs, DoS, and user/cloudId spoofing via X-Forge-Cloud-Id/X-Forge-Installation-Id are out of scope.\u003c/li\u003e\n\u003cli\u003eVia that unauthenticated /forgeWebhook, an attacker-supplied bearer is persisted as a tenant's Forge OAuth token (updateOAuthToken/setForgeOAuthToken) and later used for outbound Jira calls. Token poisoning, credential overwrite, and downstream effects are out of scope.\u003c/li\u003e\n\u003cli\u003eThe \"vversion\" endpoint (vversion/{id}) has no auth/authorization/licence check and is gated only by hard-coded magic GUIDs. Cross-tenant data dump, tenant/account deletion (DELETE_USER_ACCT + hellYeah=true), cross-tenant template copy, archive restore, and datastore-wide migration/deletion are out of scope.\u003c/li\u003e\n\u003cli\u003eThe Forge \"stmProxyJira\" resolver forwards caller-controlled url/method/body via api.asApp() with only a \"/rest/api/\" prefix check, bypassing the caller's Jira permissions. Resulting privilege escalation (arbitrary issue create/edit/transition/delete, user/group enumeration, config access) and the broader pattern of all resolvers using api.asApp() without a req.context check are out of scope.\u003c/li\u003e\n\u003cli\u003egetAuditStep validates the projectId parameter but not the fetched audit job's (parentId) ownership (checks commented out). IDOR disclosure of audit-step content (REST bodies, field values, assignees, issue keys) for jobs the caller doesn't own is out of scope.\u003c/li\u003e\n\u003cli\u003egetCreateIssuesData returns bulk-create results looked up only by a client \"reference\", with no caller/owner check, and those references are generated client-side with Math.random() (predictable). IDOR or brute-force disclosure of others' results is out of scope.\u003c/li\u003e\n\u003cli\u003eremoveTemplate/removeExecutor/saveTemplate/saveExecutor gate their ownership and permission checks behind a stored app-version check (appVersion \u0026gt;= PERMISSIONS_ACTIVE_VERSION), so on older tenants the checks are skipped while delete/update still runs. Cross-project read/overwrite/deletion (including GLOBAL/-1) is out of scope.\u003c/li\u003e\n\u003cli\u003eimportData lacks the Jira-admin check its siblings have and binds uploaded JSON straight onto persistence classes (mass assignment), and the destination projectKey is concatenated unencoded into a Jira REST path. Bulk cross-project template/executor overwrite, internal-field injection, and projectKey path manipulation are out of scope.\u003c/li\u003e\n\u003cli\u003ecreateExamples loads examples1.properties by a CWD-relative path and substitutes unescaped user values into JSON before Gson parsing (JSON injection / mass assignment); convertTmToStm uses a hard-coded AES-CBC key (no integrity) and merges the decrypted remote response into the tenant's access-control/group config. Both (admin-gated) are out of scope.\u003c/li\u003e\n\u003cli\u003emoveTemplate/moveExecutor authorize the source project but not the destination projectId, letting an admin of one project move objects into another project or GLOBAL. Out of scope.\u003c/li\u003e\n\u003cli\u003eIdentificationToken (sharedSecret, public key, OAuth credentials, Forge token) is serialized to logs at INFO (\"IDTOK=\"), as is full app-properties/group/role config, OAuth-token fragments, full JWTs on failure, full request bodies, and complete header dumps (incl. Authorization/x-forge-oauth-*). Secret/PII disclosure to anyone with log access is out of scope.\u003c/li\u003e\n\u003cli\u003eCron/maintenance endpoints (/cron/purgeOldRecords/..., /cronBackup/backupData/..., backup-service calls) are protected only by a single hard-coded UUID committed to source and shared across purge/backup/workflow-result; the destructive purge also lacks the production guard the others have. Triggering mass deletion, full-tenant backup/export, or workflow-result processing via this token is out of scope.\u003c/li\u003e\n\u003cli\u003eEndpoints loop over user arrays without size caps or length-match validation (deleteIssues, getExecutorForTemplates/getTemplatesForExecutors) and read request bodies without a content-length limit. Resource-exhaustion DoS and the related ArrayIndexOutOfBounds/NullPointerException conditions are out of scope.\u003c/li\u003e\n\u003cli\u003eProcessTask authenticates only by presence of X-AppEngine-TaskName and trusts the deserialized IdentificationToken without re-resolving the tenant; the static-file/React loader builds resource and Velocity-template paths from the request URI without canonicalization/traversal rejection. Out of scope.\u003c/li\u003e\n\u003cli\u003eThe Connect Custom-UI React runs eval() on component/icon names taken from server-stored, user-edited template/executor config (React.createElement(eval(cf.component), ...)), giving stored XSS / arbitrary JS in the rendering user's browser. All variants out of scope.\u003c/li\u003e\n\u003cli\u003eThe Connect pages have many XSS/injection sinks: Velocity renders request values (issueId, issueKey, projectId, mode, returnUrl, userId) unescaped into inline \u0026lt;script\u0026gt; and attributes (incl. unquoted monitorForExecutors($issueId) and stored error text in subTaskManagerErrors.vm); jQuery injects server/Jira/issue strings via .html(), unescaped data-* attributes, string-built onclick, attribute-selector concatenation, and .html() round-tripping; server objects are serialized raw into \u0026lt;script\u0026gt;. All resulting reflected/stored XSS, HTML/JS/JSON injection, and Velocity SSTI are out of scope.\u003c/li\u003e\n\u003cli\u003eredirectToBulkRun reflects unencoded query params (mode, issues, link, startIssue) into window.location.replace, and REST/JQL URLs are built without encodeURIComponent. Open-redirect and parameter/JQL injection of this form are out of scope.\u003c/li\u003e\n\u003cli\u003eLicence enforcement and access-control (\"access denied\") exist only in the React frontends (license.js/accessDenied.js, with a client-influenceable licence override) and are bypassable by calling backend endpoints directly. Any bypass relying on a missing equivalent server-side check is out of scope.\u003c/li\u003e\n\u003cli\u003eSecrets are committed/hard-coded: a GitHub PAT in .ci_settings.xml, an NVD API key in pom.xml, the identifier-token AES key (ECB mode), the conversion-flow AES key, and the cron/backup path UUIDs. Disclosure or use of these is out of scope.\u003c/li\u003e\n\u003cli\u003eForge triggers forward attacker-influenced webhook payloads (user, issue, comment, changelog) to the backend and convert ADF/wiki to HTML without neutralizing javascript:/data: URIs or stripping \u0026lt;iframe\u0026gt;/embed-card markup. Acting-user spoofing and stored XSS/clickjacking via the generated HTML are out of scope.\u003c/li\u003e\n\u003cli\u003eBroad-privilege/weak-hardening observations are out of scope: the Connect descriptor requests global ADMIN (plus PROJECT_ADMIN/DELETE); the Forge manifest grants manage:jira-configuration and write:jira-work with wildcard egress (*.appspot.com, *.atlassian.net) and a CSP allowing unsafe-inline/unsafe-eval; the Connect pages set no CSP or frame-ancestors.\u003c/li\u003e\n\u003cli\u003eKnown-vulnerable/unmaintained dependencies and tooling are out of scope: react-scripts 5.0.1 (vulnerable nth-check/postcss/webpack-dev-server), crypto-js \u0026lt; 4.2.0 (CVE-2023-46233), mismatched react-router majors, jQuery 3.3.1 from CDN without SRI (CVE-2019-11358), outdated endpoints-framework and OWASP dependency-check, missing JS lockfiles/floating ranges, and a non-profile-gated JDWP debug-agent config.\u003c/li\u003e\n\u003cli\u003eMinor hardening observations are out of scope: endpoints returning raw config maps or full stack traces; Long ==/!= identity comparisons and pre-auth parameter parsing; fail-soft JWT verification with non-thread-safe shared static state; synthetic user attribution on restore/bulk paths; getTemplatesForProject omitting the permission check and trusting the page parameter; decodeForHtml-only handling of template name/description/link; and verbose console logging of tokens/payloads/context.\n### Custom Fields\u003c/li\u003e\n\u003cli\u003eField value access/updates restricted solely by field security, ignoring project/issue view permissions.\u003c/li\u003e\n\u003cli\u003eThe internal \"vversion\" maintenance method and anything reachable through it (unauthenticated state changes, cross-tenant access, or deletion via guessed/known IDs) — being removed.\u003c/li\u003e\n\u003cli\u003eAuthorization/access-control inconsistencies in field-value save operations on the Forge API variant (admin allow/deny quirks, project-field vs issue-field permission differences).\u003c/li\u003e\n\u003cli\u003eStored or reflected HTML/rich-text XSS, including any sanitizer bypass, outdated, or overly permissive sanitizer policy.\u003c/li\u003e\n\u003cli\u003eFindings based solely on a third-party dependency version (sanitizer, test framework, API/endpoints framework, rich-text editor, transitive packages) or raw CVE/scanner output with no working exploit.\u003c/li\u003e\n\u003cli\u003eUnauthenticated page-load/HTML shell endpoints (including React page-load routes) and any reflected-parameter, open-redirect, or framing/clickjacking issue arising from them.\u003c/li\u003e\n\u003cli\u003eREST integration token handling — encryption mode, key management, lack of expiry/rotation, and exposure of an installation's own token to its own authenticated Jira admin.\u003c/li\u003e\n\u003cli\u003eCORS configuration on the API, including permissive origin matching and credentialed CORS responses.\u003c/li\u003e\n\u003cli\u003eWebhook error-handling/logging behaviour, including failed-auth requests processed before rejection and request-body logging.\u003c/li\u003e\n\u003cli\u003eResource-consumption/DoS against search, backup, bulk, or query operations (large result sets, unbounded queries, in-memory loading, expensive regex), including self-DoS limited to your own tenant.\u003c/li\u003e\n\u003cli\u003eScheduled-task/cron endpoints (purge, backup) — reports relying on spoofing the App Engine cron-only header or on knowing a published config identifier.\u003c/li\u003e\n\u003cli\u003eSSRF where the outbound destination derives from the platform-provided request URL or the installation's own verified base URL (no attacker-controlled host).\u003c/li\u003e\n\u003cli\u003eMissing or weak HTTP security response headers (CSP, X-Content-Type-Options, X-Frame-Options) and missing Content-Type on static assets, absent a demonstrated exploit.\u003c/li\u003e\n\u003cli\u003eStatic-asset/resource path handling (normalization, missing-file handling) where impact is limited to packaged content or a non-exploitable error response.\u003c/li\u003e\n\u003cli\u003eVerbose application logging of tokens, identifiers, claim sets, or request bodies.\u003c/li\u003e\n\u003cli\u003eMass-assignment/input-trust on the field, validator, saved-search, and configuration write APIs where access stays correctly scoped to the authenticated tenant.\u003c/li\u003e\n\u003cli\u003eThe identity/context (\"identifier\") auth mechanism and any weakness in it — client-side/symmetric encryption of identity data, secrets in the JS bundle, and the backend trusting a client-supplied identity value, including forging/replaying/tampering it to assert another identity, tenant, project, or entitlement and any resulting cross-tenant read/write/delete.\u003c/li\u003e\n\u003cli\u003eClient-side license/entitlement enforcement (bypassing a \"not licensed\" screen, build-time overrides, asserting an active license to the backend); unlicensed use is a licensing matter, not a vulnerability.\u003c/li\u003e\n\u003cli\u003eExposure of an installation's own REST/integration token to its own authenticated admin (shown on the admin config screen, held in client state, or copied by the owning admin).\u003c/li\u003e\n\u003cli\u003eThe app's CSP and iframe content settings (inline scripts/styles or eval in its own UI) and any DOM-based finding depending on them, absent a concrete cross-user exploit.\u003c/li\u003e\n\u003cli\u003eThe breadth of declared egress/permission allowlists or requested product scopes (wildcard fetch domains, seemingly broad scopes), absent a demonstrated exploit.\u003c/li\u003e\n\u003cli\u003eClient-side encoding of identifiers in API paths/query strings and parameter/path handling on calls to the app's own backend, where no cross-tenant or privilege-boundary impact is shown.\u003c/li\u003e\n\u003cli\u003eClient-side info exposure/config observations — debug/console logging, third-party UI-component license keys in the bundle, i18n/translation handling — absent a concrete exploit.\n### Watch It\u003c/li\u003e\n\u003cli\u003eEmail contents.\u003c/li\u003e\n\u003cli\u003eHardcoded outbound API keys; unauthenticated legacy vversion/admin endpoints; weak static crypto; Forge header trust without signature verification; dashboard HTML injection; token material in logs; client-controlled Jira URL fetch surface.\u003c/li\u003e\n\u003cli\u003eAny forging, tampering, decryption, or replay of the client-supplied identity / authorization payload (the \"sender\" / \"identifier\" / \"currentPage\" value and the accompanying \"contextlicense\" value) that the front-end builds from page, projectId, issueId, licenseActive, cloudId, accountId, siteUrl and timestamp, including any impersonation of another account, project, tenant/cloudId, or license state achieved through it. Known and tracked.\u003c/li\u003e\n\u003cli\u003eForging, tampering, decrypting, or replaying the client-supplied identity/authorization payload (the \"sender\"/\"identifier\"/\"currentPage\" and \"contextlicense\" values built from page, projectId, issueId, licenseActive, cloudId, accountId, siteUrl, timestamp), including impersonating another account, project, tenant/cloudId, or license state.\u003c/li\u003e\n\u003cli\u003eRecovering or using the symmetric key embedded in the shipped bundles and source maps that protects the client identity payload, and any weakness in its cipher mode, hash-derived key, or missing IV/MAC/integrity/replay protection.\u003c/li\u003e\n\u003cli\u003eBackend trust of client-supplied identity, tenant, project, or license selectors passed as parameters or headers (projectId, cloudId, clientKey, accountId, identifier, sender, contextlicense, X-Cloud-Id, X-Forge-Cloud-Id, X-Forge-Source, X-Forge-Timer, X-Watch-It-Source, X-Forge-Installation-Id) for routing, identity, tenant selection, or authorization instead of a server-verified token.\u003c/li\u003e\n\u003cli\u003eUnauthenticated submission of forged Forge webhook or issue-update events to the Connect ingress (e.g. /forgeWebhook, /issueUpdated) accepted on request markers/headers rather than a verified Forge app token, including selecting the target tenant via a header to generate notifications/emails or inject content for any tenant.\u003c/li\u003e\n\u003cli\u003eOverwriting, poisoning, or denial-of-service of a tenant's stored OAuth/credential material via header-gated ingress paths (e.g. updateOAuthToken, registerCloudId).\u003c/li\u003e\n\u003cli\u003eAny servlet, filter, or code path that skips or weakens JWT/token validation based on the presence or value of a request header (e.g. a \"forge source\" or \"watch-it source\" marker).\u003c/li\u003e\n\u003cli\u003eUsing the static per-tenant REST bearer token (\"RESTAuthToken\") to read, create, modify, enumerate, or delete watcher data across projects, including the token carrying no per-user/role/project scope, being returned to or settable from the browser, or being compared in non-constant time.\u003c/li\u003e\n\u003cli\u003eInvoking maintenance, version, statistics, delete-account, or config-migration operations gated only by a hardcoded identifier (magic GUID/string) and/or a fixed query flag rather than an authenticated authorized session, including destructive cross-tenant deletion, cross-install config rewriting, or aggregate/global statistics disclosure.\u003c/li\u003e\n\u003cli\u003eDiscovering the static identifiers, magic GUIDs, or query flags that gate maintenance/administrative operations from source, front-end bundles, source maps, backup files, or decompiled artifacts.\u003c/li\u003e\n\u003cli\u003eMissing, incorrect, inverted, or skipped per-user/role/project authorization on tenant-scoped Connect or Forge endpoints (project config, watchers, timed watchers, watcher rules, access-permission settings, audit/notification history, exports, page loads), including a non-admin or wrong-project user reading or modifying another project's data or webhook configuration.\u003c/li\u003e\n\u003cli\u003eInsecure direct object references where an object id (watcher id, audit/notification id, etc.) is not verified to belong to the project/context in the request, exposing another project's or watcher's data, history, recipients, or message bodies.\u003c/li\u003e\n\u003cli\u003eReassignment or mass-assignment of fields the caller should not control (e.g. a watcher or rule \"owner\") via client-supplied values on create/update.\u003c/li\u003e\n\u003cli\u003eConfused-deputy access where server-side or Forge resolver code makes Jira API calls with the app's own elevated credentials based on a client-supplied project id without verifying the caller's access (e.g. create-metadata, fields).\u003c/li\u003e\n\u003cli\u003eAbuse of the attachment/image proxy servlet authorized only by an HMAC whose signing key is hardcoded in source, including forging signed URLs, retrieving another tenant's attachments/resources via stored credentials, reaching non-attachment paths via lax path validation, cross-tenant replay, or timing attacks on the signature comparison.\u003c/li\u003e\n\u003cli\u003eServer-side request forgery via outbound requests whose destination is taken from stored or admin-configured data (notably timed-watcher webhook targets) without an egress allow-list or protection against internal, link-local, or cloud-metadata ranges.\u003c/li\u003e\n\u003cli\u003eStored or reflected XSS / HTML injection in notification emails from Jira issue-derived fields (summary, status, assignee/display names, description) rendered without consistent output encoding, including paths that decode previously escaped markup back into live HTML.\u003c/li\u003e\n\u003cli\u003eStored or reflected XSS in the Forge dashboard/notification gadget from Jira change data rendered as raw HTML (dangerouslySetInnerHTML/innerHTML), including XSS relying on the HTML sanitizer being bypassed, out of date, or too permissive.\u003c/li\u003e\n\u003cli\u003eHTML/content injection from the wiki-markup/ADF-to-HTML conversion in Forge triggers that fails to consistently escape interpolated text/attributes, enforce a URL-scheme allow-list on links/images, or suppress frames from card nodes (dangerous schemes, attribute breakout, tracking pixels, embedded iframes).\u003c/li\u003e\n\u003cli\u003eInjection into stored configuration or watcher conditions from user-controlled values (e.g. component/field value id and name) concatenated into stored JSON or condition strings without proper encoding.\u003c/li\u003e\n\u003cli\u003eBreakout from an inline-script or HTML context via server-rendered configuration- or translation-derived strings (e.g. event-type labels) emitted without context-appropriate encoding.\u003c/li\u003e\n\u003cli\u003e Recovering or using secrets in the source tree, version-control history, backup/\".backup\"/\".bak\" files, compiled jars, browser bundles, or source maps, including the client-identity encryption key, the attachment-proxy HMAC signing key, and the third-party email-API key.\u003c/li\u003e\n\u003cli\u003eInformation disclosure via verbose error messages or stack traces returned to clients, or logging of sensitive data (full config/property maps, tokens, decrypted authentication material, OAuth token fragments, full issue/notification content, or JWTs in the browser console).\u003c/li\u003e\n\u003cli\u003eDisclosure of backend hostnames/endpoints (including non-production hosts), customer-specific conditionals, third-party integration ids, or other implementation/topology detail present in shipped front-end source, HTML templates, or source maps.\u003c/li\u003e\n\u003cli\u003eLicense, entitlement, or paywall bypass via client-side license logic, host-name-based license overrides, or the forwarded license flag, where licensing is not yet enforced server-side.\u003c/li\u003e\n\u003cli\u003eFindings that the Forge manifest egress allow-list (including wildcard cloud domains), granted scopes (including unused elevated scopes), or content-security policy (including inline/eval script) are broader than strictly necessary.\u003c/li\u003e\n\u003cli\u003eThird-party script inclusion in application iframes without subresource integrity (e.g. analytics/changelog widgets such as Beamer) or related supply-chain exposure of these embedded widgets.\u003c/li\u003e\n\u003cli\u003eOutdated or vulnerable dependency versions, npm-audit output, or dependency CVEs (e.g. react-scripts and its transitive chain, crypto-js below 4.2.0, dated i18n libraries) without a demonstrated novel, application-specific exploit not already covered here.\u003c/li\u003e\n\u003cli\u003eTiming-oracle or non-constant-time comparison findings against secret, token, or signature comparisons.\u003c/li\u003e\n\u003cli\u003eInternal cron, task-queue, or scheduled-trigger endpoints that rely on platform-provided headers (e.g. App Engine cron/task headers) and/or static in-source path tokens for trust.+ Document Vault: Broken Access Control / IDOR — reading or deleting attachments and comments belonging to Jira issues you do not have access to (root cause: prefix-match issue scoping).\n### Document Vault\u003c/li\u003e\n\u003cli\u003eupdateFile lacks issueId validation; uploads allow cross-issue files; create issue lacks project validation; resolvers (deleteAttachment, updateFile, saveComment, setStorage, getStorage, deleteStorage, setKeyValue, getKeyValue, runApiCall) lack access control; runApiCall allows arbitrary Jira APIs; get tokens leaks tokens; emails open to HTML injection.\u003c/li\u003e\n\u003cli\u003eSensitive Data Exposure — Jira/Atlassian OAuth access tokens exposed to or recoverable by the browser front-end, including any client-side \"encryption\" whose key is also shipped to the client.\u003c/li\u003e\n\u003cli\u003eSensitive Data Exposure — Jira/Forge OAuth access tokens transmitted to or returned by the external token/upload service, including a raw Bearer token disclosed during the upload-session redeem flow.\u003c/li\u003e\n\u003cli\u003eSensitive Data Exposure — hardcoded secret/cryptographic key recoverable from the client bundle or app artifact, reused for token encryption, payload decryption, and service authentication.\u003c/li\u003e\n\u003cli\u003eBroken/Weak Cryptography — app-layer payload and token protection uses AES-CBC, MD5-based key derivation, and no integrity/AEAD (malleability, padding-oracle, MD5).\u003c/li\u003e\n\u003cli\u003eBroken Cryptography / Security-Through-Obscurity — reversible client↔server payload \"encryption\" using an empty or publicly-known key; provides no confidentiality.\u003c/li\u003e\n\u003cli\u003eUse of Hardcoded/Default Cryptographic Material — fallback development RSA key and default service endpoint URLs used when configuration is absent.\u003c/li\u003e\n\u003cli\u003eBroken Authentication — forgeable service-to-service auth on the internal upload endpoint (HMAC secret defaults to a known value), and replay of internal upload actions.\u003c/li\u003e\n\u003cli\u003eStored / DOM-based XSS — rendering of user-supplied comment/markup content as HTML.\u003c/li\u003e\n\u003cli\u003eUnrestricted File Upload — files accepted with extension-only validation, no MIME/magic-byte verification, and no size limit.\u003c/li\u003e\n\u003cli\u003eSecurity Misconfiguration — weak Content Security Policy (unsafe-inline / unsafe-eval for scripts and styles).\u003c/li\u003e\n\u003cli\u003eSecurity Misconfiguration — over-broad outbound network (fetch) allowlist using wildcard domains, and excessive requested OAuth scopes.\u003c/li\u003e\n\u003cli\u003eLack of Rate Limiting / Anti-Automation — no throttling on web-trigger endpoints, including a credential-validation oracle on the API-token auth path.\u003c/li\u003e\n\u003cli\u003eInformation Disclosure — verbose error messages or stack traces returned to clients.\u003c/li\u003e\n\u003cli\u003eIDOR Enabler — predictable/enumerable storage record identifiers.\u003c/li\u003e\n\u003cli\u003eImproper Input Parsing — fragile hand-rolled multipart/form-data and query-string parsing (parser confusion / value truncation).\u003c/li\u003e\n\u003cli\u003eVulnerable/Outdated Dependencies — known-vulnerable third-party packages and bundled vendor assets (e.g. bundled TinyMCE).\u003c/li\u003e\n\u003cli\u003eBroken Access Control \n\n\u003cul\u003e\n\u003cli\u003egetGroupMembers, getProjectRoleDetail, and downloadSecuredAttachment perform no Document Vault access-level check, letting any user with a valid session enumerate group/project-role membership or download issue attachments via the app's own elevated Jira token regardless of configured access.\u003c/li\u003e\n\u003cli\u003ewrite endpoints trust client-supplied author fields (e.g. commentCreatedAuthor, fileUpdatedAuthor) without validating them against the authenticated caller, allowing forged authorship.\u003c/li\u003e\n\u003cli\u003esendEmailNotification does not restrict which Jira groups may be targeted, letting any full-access user send app-originated email to arbitrary sitewide groups.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eInjection — unescaped values are concatenated into Jira REST API URLs (issueKey on upload endpoints) and into JQL queries built by the admin migration importer.\u003c/li\u003e\n\u003cli\u003eBroken/Weak Cryptography — non-constant-time comparison of the upload-session nonce during session redemption.\u003c/li\u003e\n\u003cli\u003eInsecure Client-Side Storage — unencrypted migrated attachment/comment content is cached in browser localStorage/IndexedDB during the admin migration flow.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eThe following finding types are specifically excluded from the bounty\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eThe use of Automated scanners is strictly prohibited (we have these tools too - don't even think about using them)\u003c/li\u003e\n\u003cli\u003eDescriptive error messages (e.g. Stack Traces, application or server errors).\u003c/li\u003e\n\u003cli\u003eFingerprinting / banner disclosure on common/public services.\u003c/li\u003e\n\u003cli\u003eClickjacking and issues only exploitable through clickjacking.\u003c/li\u003e\n\u003cli\u003eLogout Cross-Site Request Forgery (logout CSRF).\u003c/li\u003e\n\u003cli\u003eContent Spoofing.\u003c/li\u003e\n\u003cli\u003ePresence of application or web browser ‘autocomplete’ or ‘save password’ functionality.\u003c/li\u003e\n\u003cli\u003eLack of Secure/HTTPOnly flags on non-sensitive Cookies.\u003c/li\u003e\n\u003cli\u003eLack of Security Speedbump when leaving the site.\u003c/li\u003e\n\u003cli\u003eWeak Captcha / Captcha Bypass.\u003c/li\u003e\n\u003cli\u003eLogin or Forgot Password page brute force and account lockout not enforced.\u003c/li\u003e\n\u003cli\u003eUsername / email enumeration.\u003c/li\u003e\n\u003cli\u003eMissing HTTP security headers, specifically (\u003ca href=\"https://owasp.org/www-project-secure-headers/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://owasp.org/www-project-secure-headers/\u003c/a\u003e), e.g.\n\n\u003cul\u003e\n\u003cli\u003eStrict-Transport-Security.\u003c/li\u003e\n\u003cli\u003eX-Frame-Options.\u003c/li\u003e\n\u003cli\u003eX-XSS-Protection.\u003c/li\u003e\n\u003cli\u003eX-Content-Type-Options.\u003c/li\u003e\n\u003cli\u003eContent-Security-Policy, X-Content-Security-Policy, X-WebKit-CSP.\u003c/li\u003e\n\u003cli\u003eContent-Security-Policy-Report-Only.\u003c/li\u003e\n\u003cli\u003eCache-Control and Pragma\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eHTTP/DNS cache poisoning.\u003c/li\u003e\n\u003cli\u003eSSL/TLS Issues, e.g.\n\n\u003cul\u003e\n\u003cli\u003eSSL Attacks such as BEAST, BREACH, Renegotiation attack.\u003c/li\u003e\n\u003cli\u003eSSL Forward secrecy not enabled.\u003c/li\u003e\n\u003cli\u003eSSL weak/insecure cipher suites.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eSelf-XSS reports will not be accepted.\n\n\u003cul\u003e\n\u003cli\u003eSimilarly, any XSS where local access is required (i.e. User-Agent Header injection) will not be accepted. The only exception will be if you can show a working off-path MiTM attack that will allow for the XSS to trigger.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eVulnerabilities that are limited to unsupported browsers will not be accepted (i.e. \"this exploit only works in IE6/IE7\"). A list of supported browsers can be found \u003ca href=\"https://confluence.atlassian.com/display/Cloud/Supported+browsers\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eKnown vulnerabilities in used libraries, or the reports that an Atlassian product uses an outdated third party library (e.g. jQuery, Apache HttpComponents etc) unless you can prove exploitability.\u003c/li\u003e\n\u003cli\u003eMissing or incorrect SPF records of any kind.\u003c/li\u003e\n\u003cli\u003eMissing or incorrect DMARC records of any kind.\u003c/li\u003e\n\u003cli\u003eSource code disclosure vulnerabilities.\u003c/li\u003e\n\u003cli\u003eInformation disclosure of non-confidential information (e. g. issue id, project id, commit hashes).\u003c/li\u003e\n\u003cli\u003eThe ability to upload/download viruses or malicious files to the platform.\u003c/li\u003e\n\u003cli\u003eEmail bombing/Flooding/rate limiting.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eRules\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eData \u0026amp; Instances: Test only on your own instances. Do not affect, access, or use credentials for customer data/instances.\u003c/li\u003e\n\u003cli\u003eVulnerabilities: If you find sensitive customer data or an access vulnerability, report it immediately; do not attempt to validate or test it.\u003c/li\u003e\n\u003cli\u003eProhibited Testing: * No automated tools/scanners (violators will be banned).\u003c/li\u003e\n\u003cli\u003eNo social engineering, phishing, or unauthorized infrastructure access.\u003c/li\u003e\n\u003cli\u003eNo physical security testing of offices, employees, or equipment.\u003c/li\u003e\n\u003cli\u003eReporting: Submit in plain text only (standard image/video formats are allowed). PDFs or DOCX files will require resubmission.\u003c/li\u003e\n\u003cli\u003ePayouts: Redmoon Software fairly determines all grants/awards at its discretion. Reporters are solely responsible for any associated tax implications.\u003c/li\u003e\n\u003cli\u003eDisclosure: Follows Bugcrowd’s standard disclosure terms.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003ePublic Disclosure\u003c/h3\u003e\n\n\u003cp\u003eYou must request permission before publicly disclosing any issue. Publicly disclosing without written consent will result in bounty withdrawal and program disqualification.\u003c/p\u003e\n\n\u003ch3\u003eSafe Harbor\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eVulnerability research conducted under this policy is considered:\u003c/li\u003e\n\u003cli\u003eAuthorized: Under the CFAA (and state laws); we won't pursue legal action for accidental, good-faith violations.\u003c/li\u003e\n\u003cli\u003eDMCA Exempt: We won't bring claims for circumventing technological controls.\u003c/li\u003e\n\u003cli\u003eTerms Exempt: Relevant restrictions in our Terms \u0026amp; Conditions are waived on a limited basis.\u003c/li\u003e\n\u003cli\u003eLawful \u0026amp; Helpful: Recognized as good-faith contributions to internet security.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eYou must still comply with all applicable laws. If uncertain whether your research aligns with this policy, submit a report through an Official Channel before proceeding.\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"dc192818-b632-4b43-992f-dfbbb108e348","name":"In Scope Targets","targets":[{"id":"d17eee90-70fa-4fbd-8f19-efa50b874d7f","uri":"https://marketplace.atlassian.com/apps/1213649/custom-fields-for-jira-cloud?hosting=cloud\u0026tab=overview","name":"Custom Fields for Jira Cloud - https://marketplace.atlassian.com/apps/1213649/custom-fields-for-jira-cloud?hosting=cloud\u0026tab=overview","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"5a9e75aa-9c08-4a6d-9092-3d42e8d0efda","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"d17eee90-70fa-4fbd-8f19-efa50b874d7f"}],"recentChangeFlags":null},{"id":"24ddead9-ad59-4f3a-baf4-fbab31a9b4d7","uri":"https://marketplace.atlassian.com/apps/1214056/sub-task-manager-for-jira?hosting=cloud\u0026tab=overview","name":"Sub Task Manager for Jira - Cloud Hosted - https://marketplace.atlassian.com/apps/1214056/sub-task-manager-for-jira?hosting=cloud\u0026tab=overview","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"ff62c4fa-8810-4487-8cb2-2c549009bd9f","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"24ddead9-ad59-4f3a-baf4-fbab31a9b4d7"}],"recentChangeFlags":null},{"id":"fc6f07cb-b744-481e-822c-13a58f02eb27","uri":"https://marketplace.atlassian.com/apps/1213851/watch-it-for-jira-cloud?hosting=cloud\u0026tab=overview","name":"Watch It for Jira Cloud - https://marketplace.atlassian.com/apps/1213851/watch-it-for-jira-cloud?hosting=cloud\u0026tab=overview","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"f208f571-bd21-4a92-ae93-dbd84a6bc2bb","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"fc6f07cb-b744-481e-822c-13a58f02eb27"}],"recentChangeFlags":null},{"id":"9e2ea694-2079-4aa3-a195-13a59cd3a467","uri":"https://marketplace.atlassian.com/apps/1211639/comment-history-for-jira?hosting=cloud\u0026tab=overview","name":"Comment History for Jira Cloud - https://marketplace.atlassian.com/apps/1211639/comment-history-for-jira?hosting=cloud\u0026tab=overview","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"d45e2c73-3f2d-43ef-8039-9acc81bc862d","sortOrder":6},"sortOrder":6,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"9e2ea694-2079-4aa3-a195-13a59cd3a467"}],"recentChangeFlags":null},{"id":"7b618973-b213-48e4-bf1a-05bc04a88638","uri":"https://marketplace.atlassian.com/apps/1211880/document-vault-secure-attachments-in-jira?tab=installation\u0026hosting=cloud","name":"Document Vault for Jira Cloud - https://marketplace.atlassian.com/apps/1211880/document-vault-secure-attachments-in-jira?tab=installation\u0026hosting=cloud    ","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"f8ffa71b-8831-41a5-aea1-8817b25b7b2a","sortOrder":6},"sortOrder":6,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"7b618973-b213-48e4-bf1a-05bc04a88638"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":{"id":"c834570f-26c6-44e1-9bba-5edeaba825fa","p1MaxCents":150000,"p1MinCents":150000,"p2MaxCents":90000,"p2MinCents":90000,"p3MaxCents":30000,"p3MinCents":30000,"p4MaxCents":10000,"p4MinCents":10000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":null,"rewardRangeData":{"1":{"min":1500,"max":1500},"2":{"min":900,"max":900},"3":{"min":300,"max":300},"4":{"min":100,"max":100},"5":{"min":null,"max":null}},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"442d780f-fccd-4501-a759-684811f12797","code":"redmoon","state":"in_progress","endsAt":null,"bountyId":"e4d16aaa-82c3-4466-8e5f-0109f81312f6","startsAt":"2020-07-21T18:00:00Z"},"vrtScopeRules":[],"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Electronics","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/42f5/8745/ab12ce76/6b6f69b6e0643bf8635c6f6ae27cf06e_Redmoon_Portrait_Logo_Red_Blue_144x144.png","logoBackgroundColor":"#fcfcfc","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2020-07-21T18:00:00.000Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/redmoon","changelogs":"/engagements/redmoon/changelog","submissions":null,"announcements":"/engagements/redmoon/announcements","hallOfFame":"/engagements/redmoon/hall_of_fames","crowdstream":"/engagements/redmoon/crowdstream"},"announcementsCount":1,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/redmoon/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=redmoon\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/redmoon/engagement_subscribers","engagementChangelogsUrl":"/engagements/redmoon/changelog","publishedAt":"2026-07-30T23:27:10.503Z","engagementChangelogUrl":"/engagements/redmoon/changelog/b324d66b-aa06-497b-ae39-5ea7c4442c27","createUserFeedbacksUrl":"/engagements/redmoon/feedbacks","engagementCrowdstreamUrl":"/engagements/redmoon/crowdstream","acceptedSubmissionsEnabled":false,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}