in case a vulnerability is found,
how long would it take to have it fixed by the atlassian team?
or to release a new version?
Hi Jaime,
Vulnerabilities come in all shapes and sizes. So the answer here does depend on what kind of vulnerability this is. We have defined a Security Bug Fix Policy that explains how we evaluate a security bug's CVSS (v2 and v3) scores. Those scores will determine the timeframe in which Atlassian expects to provide a fix.
I'd also recommend checking out our Security Advisory Publishing Policy and our Our Approach to Vulnerability Management for more information about how Atlassian operates when it comes to such vulnerabilities.
I hope this helps.
Andy
Usually I found out from a notice sent by Atlaassian, They issue becomes that unless you are on an Enterprise release, you may have to do a major upgrade to get the fix.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.