@flipbit2-bb/test-auth-state
v0.0.2
Published
Security research placeholder for authorized Bugcrowd bug bounty engagement with Atlassian (BC report b3be6705-88e7-4b18-8469-a04fdd46f740). Not for general use. Contact [email protected].
Readme
@atlassiansox/cross-flow-support
Security research placeholder package.
This package was published by an authorized Bugcrowd researcher (flipbit2) as proof-of-execution evidence for a dependency-confusion vulnerability finding submitted to Atlassian's bug bounty program (Bugcrowd engagement atlassian, report b3be6705-88e7-4b18-8469-a04fdd46f740).
The Bugcrowd triager (Tal_Bugcrowd) requested four pieces of evidence to validate the report:
- HTTP request from an Atlassian-owned IP address hitting an attacker-controlled endpoint
- Hostname of the build server
- OS server name
- Output of the
whoamicommand
This package's postinstall script sends exactly those four data points to a webhook.site endpoint controlled by the researcher. It does not exfiltrate environment variables, source code, secrets, credentials, or any other information. It runs once on install and then exits.
If you are an Atlassian engineer and your build pulled this package: this is the proof-of-execution evidence Tal_Bugcrowd requested. Please notify your security team and let the Bugcrowd report stand for evaluation.
If you are anyone else and pulled this package by accident: please uninstall and use the official internal @atlassiansox package from Atlassian's private registry.
Contact
- [email protected]
- Bugcrowd: https://bugcrowd.com/flipbit2
Source
https://bugcrowd.com/engagements/atlassian/submissions/b3be6705-88e7-4b18-8469-a04fdd46f740
