Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Experience with fix and updates?

Jaime Murillo September 22, 2020

in case a vulnerability is found, 
how long would it take to have it fixed by the atlassian team? 

or to release a new version? 

2 answers

1 accepted

0 votes
Answer accepted
Andy Heinzer
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
September 22, 2020

Hi Jaime,

Vulnerabilities come in all shapes and sizes. So the answer here does depend on what kind of vulnerability this is.  We have defined a Security Bug Fix Policy that explains how we evaluate a security bug's CVSS (v2 and v3) scores.  Those scores will determine the timeframe in which Atlassian expects to provide a fix.

I'd also recommend checking out our Security Advisory Publishing Policy and our Our Approach to Vulnerability Management for more information about how Atlassian operates when it comes to such vulnerabilities.

I hope this helps.

Andy

0 votes
Bill Bailey
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
September 22, 2020

Usually I found out from a notice sent by Atlaassian,  They issue becomes that unless you are on an Enterprise release, you may have to do a major upgrade to get the fix.

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events