As cited
Copy frozen at (site build).
vulnerabilities
Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers
Atlassian's Rovo AI assistant can be manipulated through attacker-controlled instructions to exfiltrate Jira and Confluence data accessible to the authenticated user, then transmit it to external servers. Two security firms discovered this vulnerability through different attack methods, though only one exploitation path has been confirmed patched.
Why it matters: Atlassian Cloud users relying on Rovo for data access face data exfiltration risk from malicious prompts; defenders should review Rovo permissions and update to patched versions immediately.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers
No summary had been written when this copy was frozen.
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers
Attackers can embed malicious instructions in files that Atlassian's Rovo assistant processes, causing it to extract accessible Jira or Confluence data from a signed‑in user. Two security firms discovered the issue independently, and while one exploitation path has been patched, the other remains open.
Why it matters: Atlassian Rovo users risk having Jira or Confluence data accessed by attackers via malicious file uploads; they should verify that the disclosed exploitation path is patched and audit Rovo permissions and file‑input controls.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers
Attackers can embed malicious instructions in files that Atlassian's Rovo assistant processes, causing it to extract accessible Jira or Confluence data from a signed‑in user. Two security firms discovered the issue independently, and while one exploitation path has been patched, the other remains open.
Why it matters: Atlassian Rovo users risk having Jira or Confluence data accessed by attackers via malicious file uploads; they should verify that the disclosed exploitation path is patched and audit Rovo permissions and file‑input controls.
- Source published
- First seen by Cybersecurity Tracker