| |
Atlassian Rovo Exfiltrates Data, Bypassing Controls
Atlassian's Rovo AI contains vulnerabilities that allow attackers to exfiltrate sensitive data such as Jira tickets and Confluence documents through indirect prompt injection attacks embedded in uploaded files. The attack bypasses security controls by exploiting Rovo's URL retrieval tool and succeeds even when web search is disabled organization-wide. Security researchers disclosed the vulnerabilities to Atlassian on May 23rd, but after over two months without fixes, they are now publicly disclosing the risks to alert users.
Read Full Article →
← More Tech news