Severity Levels for Security Issues | Atlassian (2024)

Sources of Vulnerability

  • Security scanner tickets such as those filed by Nexpose and Snyk
  • Bug bounty findings found by security researchers through Bugcrowd
  • Security vulnerabilities reported by the security team as part of reviews
  • Security vulnerabilities reported by Atlassians

Severity Framework and Rating

Atlassian uses Common Vulnerability Scoring System (CVSS) as a method of assessing security risk and prioritization for each discovered vulnerability. CVSS is an industry standard vulnerability metric. You can learn more about CVSS atFIRST.org.

Severity Levels

Atlassian security advisories include a severity level. This severity level is based on our self-calculated CVSS score for each specific vulnerability.

  • Critical
  • High
  • Medium
  • Low

For CVSS v3 Atlassian uses the following severity rating system:

CVSS V3 SCORE RANGE
SEVERITY IN ADVISORY

9.0 - 10.0

Critical

7.0 - 8.9

High

4.0 - 6.9

Medium

0.1 - 3.9

Low

In some cases, Atlassian may use additional factors unrelated to CVSS score to determine the severity level of a vulnerability. This approach is supported by the CVSS v3.1 specification:

Consumers may use CVSS information as input to an organizational vulnerability management process that also considers factors that are not part of CVSS in order to rank the threats to their technology infrastructure and make informed remediation decisions. Such factors may include: number of customers on a product line, monetary losses due to a breach, life or property threatened, or public sentiment on highly publicized vulnerabilities. These are outside the scope of CVSS.

In cases where Atlassian takes this approach, we will describe which additional factors have been considered and why when publicly disclosing the vulnerability.

Below are a few examples of vulnerabilities which mayresult in a given severity level. Please keep in mind that this rating does not take into account details of your installation and are to be used as a guide only.

Severity Level: Critical

Vulnerabilities that score in the critical range usually havemostof the following characteristics:

  • Exploitation of the vulnerability likely results in root-level compromise of servers or infrastructure devices.
  • Exploitation is usually straightforward, in the sense that the attacker does not need any special authentication credentials or knowledge about individual victims, and does not need to persuade a target user, for example via social engineering, into performing any special functions.

For critical vulnerabilities, is advised that you patch or upgrade as soon as possible, unless you have other mitigating measures in place. For example, a mitigating factor could beif your installation is not accessible from the Internet.

Severity Level: High

Vulnerabilities that score in the high range usually havesomeof the following characteristics:

  • The vulnerability is difficult to exploit.
  • Exploitation could result in elevated privileges.
  • Exploitation could result in a significant data loss or downtime.

Severity Level: Medium

Vulnerabilities that score in the medium rangeusually have someof the following characteristics:

  • Vulnerabilities that require the attacker to manipulate individual victims via social engineering tactics.
  • Denial of service vulnerabilities that are difficult to set up.
  • Exploits that require an attacker to reside on the same local network as the victim.
  • Vulnerabilities where exploitation provides only very limited access.
  • Vulnerabilities that require user privileges for successful exploitation.

Severity Level: Low

Vulnerabilities in the low range typically havevery little impacton an organization's business. Exploitation of such vulnerabilities usually requires local or physical system access. Vulnerabilities in third party code that are unreachable from Atlassian code may be downgraded to low severity.

Remediation Timeline

Atlassian sets service level objectives for fixing security vulnerabilities based on the security severity level and the affected product. We have defined timeframes for fixing security issues according to our security bug fix policy.

Accelerated Resolution Timeframes apply to:

  • All cloud-based Atlassian products
  • Jira Align (both the cloud and self-managed versions)
  • Any other software or system managed by Atlassian, or running on Atlassian infrastructure

Extended Resolution Timeframes apply to:

  • All self-managed Atlassian products
    • These are products that are installed by customers on customer-managed systems
    • This includes Atlassian's Data Center, desktop, and mobile applications

CVSS Resolution Timeframe

Severity levels
Accelerated Resolution Timeframes
Extended Resolution Timeframes

Critical

Within 10 days of being verified Within 90 days of being verified

High

Within 4 weeks of being verified Within 90 days of being verified

Medium

Within 12 weeks of being verified Within 90 days of being verified

Low

Within 25 weeks of being verified Within 180 days of being verified
Severity Levels for Security Issues | Atlassian (2024)
Top Articles
M-PESA
Remitly: Send Money from Diaspora to Kenya
Katie Pavlich Bikini Photos
Craigslist Monterrey Ca
Weeminuche Smoke Signal
Repentance (2 Corinthians 7:10) – West Palm Beach church of Christ
Algebra Calculator Mathway
What Are the Best Cal State Schools? | BestColleges
Craglist Oc
THE 10 BEST Women's Retreats in Germany for September 2024
Missing 2023 Showtimes Near Landmark Cinemas Peoria
Blue Beetle Showtimes Near Regal Swamp Fox
David Turner Evangelist Net Worth
Restaurants Near Paramount Theater Cedar Rapids
Dc Gas Login
X-Chromosom: Aufbau und Funktion
Pinellas Fire Active Calls
Loft Stores Near Me
Craigslist Pet Phoenix
Www.publicsurplus.com Motor Pool
Yog-Sothoth
Dtlr Duke St
If you have a Keurig, then try these hot cocoa options
Atlases, Cartography, Asia (Collection Dr. Dupuis), Arch…
Directions To Nearest T Mobile Store
100 Gorgeous Princess Names: With Inspiring Meanings
WPoS's Content - Page 34
Davita Salary
Melissa N. Comics
Wake County Court Records | NorthCarolinaCourtRecords.us
Kokomo Mugshots Busted
RUB MASSAGE AUSTIN
Mp4Mania.net1
Police Academy Butler Tech
2024 Ford Bronco Sport for sale - McDonough, GA - craigslist
Tal 3L Zeus Replacement Lid
Bay Focus
Sams La Habra Gas Price
Boone County Sheriff 700 Report
Infinite Campus Parent Portal Hall County
Fwpd Activity Log
All-New Webkinz FAQ | WKN: Webkinz Newz
Caesars Rewards Loyalty Program Review [Previously Total Rewards]
Dying Light Mother's Day Roof
The Jazz Scene: Queen Clarinet: Interview with Doreen Ketchens – International Clarinet Association
Bedbathandbeyond Flemington Nj
Craigslist Sarasota Free Stuff
Causeway Gomovies
Sml Wikia
Besoldungstabellen | Niedersächsisches Landesamt für Bezüge und Versorgung (NLBV)
32 Easy Recipes That Start with Frozen Berries
Latest Posts
Article information

Author: Rubie Ullrich

Last Updated:

Views: 5864

Rating: 4.1 / 5 (72 voted)

Reviews: 87% of readers found this page helpful

Author information

Name: Rubie Ullrich

Birthday: 1998-02-02

Address: 743 Stoltenberg Center, Genovevaville, NJ 59925-3119

Phone: +2202978377583

Job: Administration Engineer

Hobby: Surfing, Sailing, Listening to music, Web surfing, Kitesurfing, Geocaching, Backpacking

Introduction: My name is Rubie Ullrich, I am a enthusiastic, perfect, tender, vivacious, talented, famous, delightful person who loves writing and wants to share my knowledge and understanding with you.