Security Flaws in Atlassian Rovo Allow Data Exfiltration from Jira and Confluence
Security researchers have identified vulnerabilities in Atlassian's Rovo assistant that could allow attackers to exfiltrate data from Jira and Confluence. PromptArmor discovered that attacker-controlled instructions embedded in content could prompt Rovo to send internal data to an external server. Varonis Threat Labs found a separate flaw, RovoBlast, where a URL parameter could preload attacker instructions, allowing data exfiltration with a single click. Atlassian has fixed the RovoBlast flaw, but the PromptArmor issue remains unresolved as of the latest reports.