Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers
The Hacker News
Read full postTwo security firms independently discovered that Atlassian's Rovo assistant can be manipulated to extract Jira and Confluence data accessible to a signed-in user and send it to external servers. One vulnerability, involving a URL parameter, has been fixed server-side, while another, using embedded instructions in uploaded content, remains partially unconfirmed as remediated. These flaws allow attackers to exploit Rovo without explicit user approval, posing data exfiltration risks.

- Atlassian Rovo Exfiltrates Data, Bypassing Controls· Hacker News



