Atlassian Rovo가 사용자 데이터를 공격자에게 전송하는 취약점 발견.
Atlassian Rovo 어시스턴트에서 사용자 인증 정보를 이용한 데이터 수집 취약점이 발견되었습니다. 공격자가 제공한 지침에 따라 Jira나 Confluence 데이터를 수집하고 외부 서버로 전송할 수 있는 것으로 확인되었습니다. 보안 기업 PromptArmor가 이 취약점을 발견하였으며, 현재 확인된 해결책은 하나뿐입니다.
A vulnerability in Atlassian Rovo allows it to send user data to attackers.
A vulnerability has been discovered in Atlassian's Rovo assistant that allows attacker-controlled instructions to make it collect Jira or Confluence data from signed-in users and send it to external servers. This behavior was independently found by two security firms, although only one of the identified routes has been confirmed as closed. The AI security firm PromptArmor concealed the instructions in content that Rovo processes.