THREAT OPS › Threat News › RovoBlast: How One Click Triggered Atlassian’s AI Assistant to Leak Data
RovoBlast: How One Click Triggered Atlassian’s AI Assistant to Leak Data
<p>Varonis Threat Labs uncovered a vulnerability in Rovo, Atlassian's enterprise AI assistant. Dubbed RovoBlast, a single click on a link triggers the attacker's embedded instructions and forces Rovo to accept externally supplied parameters as trusted inputs within a user's session. No jailbreaks, no permission bypass, and no warnings or confirmation.</p> <p>The same capabilities that make Rovo a
MITRE ATT&CK techniques
Indicators of compromise
- https://bugcrowd.com/disclosures/bf1922fb-99d0-4d3b-b419-1728720d29ec/one-click-data-exfiltration-via-rovochatprompt-url-parameter-confluence-rovourl
- https://home.atlassian.com/chat?rovoChatPathway=chat&rovoChatPrompt=<prompt>url
- https://community.atlassian.com/forums/Rovo-articles/Why-Can-t-You-Disable-Rovo-And-What-to-do-Instead/ba-p/3159063url
- https://www.atlassian.com/software/rovo/connectorsurl
- track.hubspot.comdomain
- 2fwww.varonis.comdomain
- 252fwww.varonis.comdomain
Original source: https://www.varonis.com/blog/rovoblast