Skip to content
The Nexus
SECURITYAug 8 · 08:54 UTCTHE HACKER NEWS[email protected] (The Hacker News)

Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers

Atlassian's Rovo assistant can be exploited using attacker-controlled instructions to collect Jira or Confluence data accessible to a signed-in user, and then send this data to an outside server. The vulnerability was independently discovered by two security firms; PromptArmor identified that the malicious instructions were hidden within content that Rovo reads.

Nexus surfaces and summarizes. The full story lives at the source.

Mentioned
Spot something wrong with this article?Report a problem →
Forward this
Related Signal

Adjacent reporting

Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers · The Nexus