Jira Forge Penetration Test Required
Budget: £250 – £750 GBP
The Jira Forge cloud app is almost ready for Bugcrowd, but before I submit it I need an external security sweep that leaves zero chance of a P1–P4 slipping through. You will receive full admin access to a dedicated Jira Cloud instance (and, if useful, a second test tenant you spin up on your own account).
Scope to hit hard: user authentication flows, data-access controls inside every module, and all exposed API endpoints. Try parameter tampering—changing the createdBy USER_ID, privilege escalation, session hijacking—anything that could let a normal user act as an admin or see another employee’s data. Burp Suite is essential, and you’re free to bring any other standard tools that help you dig deeper.
Deliverables
• Comprehensive report: finding, impact, exact reproduction steps, CVSS/CWE mapping, and clear remediation advice.
• Proof-of-concept material: Burp project files, intercepted requests, scripts, or screenshots demonstrating each exploit.
• One follow-up retest after fixes to confirm the issue is fully closed.
The engagement ends when the app is clean enough that a Bugcrowd run should surface nothing critical.
Scope to hit hard: user authentication flows, data-access controls inside every module, and all exposed API endpoints. Try parameter tampering—changing the createdBy USER_ID, privilege escalation, session hijacking—anything that could let a normal user act as an admin or see another employee’s data. Burp Suite is essential, and you’re free to bring any other standard tools that help you dig deeper.
Deliverables
• Comprehensive report: finding, impact, exact reproduction steps, CVSS/CWE mapping, and clear remediation advice.
• Proof-of-concept material: Burp project files, intercepted requests, scripts, or screenshots demonstrating each exploit.
• One follow-up retest after fixes to confirm the issue is fully closed.
The engagement ends when the app is clean enough that a Bugcrowd run should surface nothing critical.
Related categories:
Web Security
Compliance
Penetration Testing
Network Security
Risk Assessment
Data Protection
API Testing