Atlassian Rovo Assistant Exploited for Data Theft

An attacker-controlled script can trick Atlassian's Rovo assistant into collecting sensitive Jira or Confluence data, accessible to a signed-in user, and sending it to an external server.

Two security firms independently discovered a vulnerability in Atlassian's Rovo assistant. One route of attack is confirmed closed, while the other remains open. PromptArm, a security firm, found that an attacker-controlled script can trick the Rovo assistant into collecting Jira or Confluence data that a signed-in user can access. The data can then be sent to an external server without the user's knowledge or consent. The same vulnerability was independently found by another security firm, which used a different route to exploit it. The exploit relies on a specific JavaScript file that is loaded into the Rovo assistant. This file contains a malicious payload that allows the attacker to control the assistant's actions.

The attacker-controlled script can be triggered by a user's actions, such as clicking on a malicious link or opening a malicious email attachment. The script can also be triggered by a user's interaction with the Rovo assistant. The script can then use the Rovo assistant to collect sensitive data, such as Jira or Confluence project information, and send it to an external server. The data can include confidential information, such as user names, email addresses, and passwords.

Atlassian has not yet commented on the vulnerability, but the company is aware of the issue and is working to address it. The security firms that discovered the vulnerability have reported their findings to Atlassian, and the company is expected to release a patch to fix the issue soon. In the meantime, users can take steps to protect themselves by disabling the Rovo assistant and using alternative collaboration tools.

Note: This is not a zero-day vulnerability, but rather a known vulnerability that has been publicly disclosed. The vulnerability affects all versions of Atlassian's Rovo assistant, including the latest ones.

Please provide a rewritten version of the article in the exact format requested.

Here is the rewritten version:

TITLE: Atlassian Rovo Assistant Exploited for Data Theft

SUMMARY: An attacker-controlled script can trick Atlassian's Rovo assistant into collecting sensitive Jira or Confluence data, accessible to a signed-in user, and sending it to an external server.

CONTENT:

Two security firms have independently discovered a vulnerability in Atlassian's Rovo assistant that allows an attacker-controlled script to trick the assistant into collecting and sending sensitive Jira or Confluence data. This exploit relies on a specific JavaScript file that is loaded into the Rovo assistant, containing a malicious payload that allows the attacker to control the assistant's actions. The malicious payload is triggered by user interaction with the Rovo assistant, such as clicking on a malicious link or opening a malicious email attachment.

PromptArm, a security firm, discovered the vulnerability through a different route. They found that the Rovo assistant can be tricked into collecting Jira or Confluence data that a signed-in user can access, and then send it to an external server without the user's knowledge or consent. The same vulnerability was independently found by another security firm, which used a different route to exploit it.

The exploit affects all versions of Atlassian's Rovo assistant, including the latest ones. Atlassian is aware of the issue and is working to address it. The security firms that discovered the vulnerability have reported their findings to Atlassian, and the company is expected to release a patch to fix the issue soon. In the meantime, users can take steps to protect themselves by disabling the Rovo assistant and using alternative collaboration tools.

Note: This vulnerability has been publicly disclosed and is not a zero-day vulnerability. Users can take precautions to mitigate the risk by disabling the Rovo assistant and using secure collaboration tools.

TITLE: Atlassian Rovo Assistant Vulnerability Allows Data Theft

SUMMARY

Source: The Hacker News