RESEARCHERS have identified a significant vulnerability called RovoBlast in Atlassian's AI assistant, enabling attackers to manipulate an authenticated user's session using a crafted URL. This flaw allows for the extraction of sensitive company data to the public web without user confirmation or warning. Disclosed by Varonis Threat Labs, the vulnerability was fixed by Atlassian following its presentation at DEF CON 34.
As Rovo functions as a bridge across various platforms like Jira and Slack, Varonis highlighted risks regarding data access and recommended tightening access, disabling unnecessary features, and regularly auditing log activities to mitigate potential risks.