Q 100 · Excellent

Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers

Atlassian's AI assistant, Rovo, has been identified with a critical vulnerability that allows attackers to exfiltrate sensitive Jira and Confluence data. The flaw enables attacker-controlled instructions to trick Rovo into collecting data a signed-in user can access and then transmitting it to an external server. This security concern was independently discovered by two separate security firms, although only one has publicly detailed its findings.

Key points
  • Atlassian's AI assistant, Rovo, has been identified with a critical vulnerability that allows attackers to exfiltrate sensitive Jira and Confluence…
InternetAug 8, 20266 min read