
The attack only required one click by the victim on a specially crafted link, which then allowed the attacker to potentially access anything Rovo is privileged.
The issue was reported to Atlassian through a bug bounty program hosted on Bugcrowd, and the company has since fixed it. The company, however, did not immediately respond to CSO’s request for comments.
Rovo’s broad access made the click worse
Varonis found that Rovo could enumerate and search data across a wide range of sources available to an organization, including Jira, Confluence, Bitbucket, Slack, Google Workspace, Microsoft 365, relational databases, uploaded files, webpages, and archives.
