Jira Forge Penetration Test Required

Job ID: 40139314

Budget: £250 – £750 GBP

The Jira Forge cloud app is almost ready for Bugcrowd, but before I submit it I need an external security sweep that leaves zero chance of a P1–P4 slipping through. You will receive full admin access to a dedicated Jira Cloud instance (and, if useful, a second test tenant you spin up on your own account).

Scope to hit hard: user authentication flows, data-access controls inside every module, and all exposed API endpoints. Try parameter tampering—changing the createdBy USER_ID, privilege escalation, session hijacking—anything that could let a normal user act as an admin or see another employee’s data. Burp Suite is essential, and you’re free to bring any other standard tools that help you dig deeper.

Deliverables
• Comprehensive report: finding, impact, exact reproduction steps, CVSS/CWE mapping, and clear remediation advice.
• Proof-of-concept material: Burp project files, intercepted requests, scripts, or screenshots demonstrating each exploit.
• One follow-up retest after fixes to confirm the issue is fully closed.

The engagement ends when the app is clean enough that a Bugcrowd run should surface nothing critical.