Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data

Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data
Varonis Threat Labs uncovered RovoBlast, a one-click vulnerability in Atlassian’s Rovo AI assistant that let attacker-controlled instructions be injected into live AI sessions through a crafted link. The flaw could expose data from Jira, Confluence, Bitbucket, Slack, Microsoft 365, Google Workspace, and other connected systems before Atlassian fixed it. #RovoBlast #Atlassian #Rovo #Varonis #DEFCON34

Keypoints

  • RovoBlast let a crafted URL seed attacker instructions into Rovo’s chat session.
  • The issue relied on parameter-to-prompt injection through the rovoChatPrompt URL parameter.
  • Rovo’s autonomous ResearchAgent could pull internal data and leak it to the web.
  • Proof-of-concepts showed exfiltration from Confluence, Jira, and SharePoint.
  • Atlassian patched the flaw after responsible disclosure from Varonis Threat Labs.

Read More: https://www.securityweek.com/critical-one-click-vulnerability-in-atlassians-rovo-ai-exposed-enterprise-data/