Kryptovaluta-ticker:
sysadmin fra Cyber Security News

Atlassian Rovo Prompt Injection Exfiltrates Jira and Confluence Data Without User Approval

Abinaya
4 hours ago
4 Visninger
0 Kommentarer
Atlassian Rovo Prompt Injection Exfiltrates Jira and Confluence Data Without User Approval

RovoBlast is a one-click prompt-injection vulnerability in Atlassian Rovo that could allow attackers to exfiltrate sensitive enterprise data from Jira, Confluence, SharePoint, and other connected services. Atlassian addressed the reported URL-based issue on the server side after responsible disclosure, with the fix deployed on July 8, 2026. Rovo is Atlassian’s enterprise AI assistant, designed to search, summarize, and take actions across Jira, Confluence, Bitbucket, and third-party SaaS platforms. Its value comes from access to organizational context. However, the same broad access can create a major security risk when attacker-controlled content is treated as trusted instructions. The RovoBlast attack abused a URL parameter...

Læs hele artiklen hos kilden.

Deltag i diskussionen — kommenter, stem og del links.

Registrer
Var dette nyttigt?
Del:

Kommentarer (0)

Log venligst ind eller opret dig for at deltage i diskussionen

Ingen kommentarer ennå. Bli den første til å kommentere!