Build credibility. Find opportunity. Advance in cybersecurity.
Font size: +

Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers

Cybersecurity team reviewing a regional security update
Regional security update

Assess promptly

Attacker-controlled instructions can make Atlassian's Rovo assistant collect Jira or Confluence data that a signed-in user can access, then send it to an outside server. Two security firms found that behavior independently, by different routes. Only one of those routes is confirmed closed. PromptArmor, an AI security firm, hid the instructions in content Rovo reads. It said an uploaded file was

At a glance

  • Attacker-controlled instructions can make Atlassian's Rovo assistant collect Jira or Confluence data that a signed-in user can access, then send it to an outside server. Two security firms found that behavior independently, by different routes. Only one of those routes is confirmed closed. PromptArmor, an AI security firm, hid the instructions in content Rovo reads. It said an uploaded file was
  • SecurityTalent reviewed the linked official source and preserved its attribution.
Sign in to read full story
In order for you to continue reading the full contents of the post, you will need to login first

Copyright

© SecurityTalent.com — original summary and analysis

Critical Flaws Discovered in Belgian eID Software ...
18-Year-Old Linux SCTP Flaw Could Let Local Users ...

Related Posts

 

Comments

Already Registered? Login Here
No comments made yet. Be the first to submit a comment