CISOOnline

One-click flaw in Atlassian Rovo exposed enterprise data via prompt injection attack

The attack only required one click by the victim on a specially crafted link, which then allowed the attacker to potentially access anything Rovo is privileged.

The issue was reported to Atlassian through a bug bounty program hosted on Bugcrowd, and the company has since fixed it. The company, however, did not immediately respond to CSO’s request for comments.

Rovo’s broad access made the click worse

Varonis found that Rovo could enumerate and search data across a wide range of sources available to an organization, including Jira, Confluence, Bitbucket, Slack, Google Workspace, Microsoft 365, relational databases, uploaded files, webpages, and archives.



Source link