One-click RovoBlast exploit leaks data from Atlassian workspaces

Two firms found independent ways to turn Atlassian's Rovo assistant into a one-click data leak.

CSBadmin
2 Min Read

Defenders should know that Rovo can be hijacked into leaking data the signed-in user can reach. Attacker-written instructions are enough to turn the Atlassian assistant into an exfiltration channel for Jira and Confluence content. Two firms found independent routes in; only one has a confirmed fix.

Varonis Threat Labs named its finding RovoBlast. The chain starts in a URL parameter called rovoChatPrompt, which preloads attacker instructions into Rovo Chat. A single click from an authenticated user is enough for Rovo to execute them with that user’s privileges and ship data out. The proof of concept lifted a private API key from Confluence, and the researchers say Jira plus data behind SharePoint and Outlook connectors are equally exposed. Filed through Bugcrowd, the report earned a $6,000 bounty and was fixed server-side on July 8.

PromptArmor hid instructions in content Rovo reads, saying an uploaded file was enough to make the assistant gather internal data and send it out through a URL request with no separate approval step. Even switching off Rovo’s web-search option did not stop the leak, according to the firm. That path has no confirmed fix.

Neither issue carries a CVE identifier. Atlassian’s mitigation for the content-borne route is scoping which apps and groups can use Rovo at all.

Enterprises running Rovo should review their web-search settings, restrict Rovo access by group, and watch for outbound requests the assistant did not initiate.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.