Critical One-Click Vulnerability in Atlassian Rovo AI Exposes Enterprise Data

www.news4hackers.com-critical-one-click-vulnerability-in-atlassian-rovo-ai-exposes-enterprise-data-critical-one-click-vulnerability-in-atlassian-rovo-ai-exposes-enterprise-data

A critical security flaw in Rovo, Atlassian’s enterprise artificial intelligence assistant, has been identified that allows malicious actors to inject unauthorized commands into active user sessions through a single interaction.

Discovery and Technical Details

The vulnerability, named RovoBlast, exploits the AI’s trust in external parameters, enabling attackers to manipulate its behavior without requiring elevated privileges or complex workarounds. Rovo serves as an AI layer integrating with core Atlassian tools such as Jira, Confluence, and Bitbucket, as well as third-party platforms like Slack, Microsoft 365, and Google Workspace.

Parameter-to-Prompt (P2P) Injection

Researchers from Varonis Threat Labs discovered that a maliciously crafted URL parameter, “rovoChatPrompt,” could directly inject content into the AI’s chat interface. This method, termed parameter-to-prompt (P2P) injection, mirrors a similar technique previously reported in Microsoft Copilot under the name Reprompt.

Flaw’s Root Cause

The flaw arises from the system’s handling of URL parameters, where the organization ID field could be omitted, allowing requests to default to the victim’s organization. This bypassed standard security checks, enabling the AI to process external inputs as legitimate.

Impact and Exploitation

Rovo revealed access to a wide range of data sources, including Jira projects, Confluence documents, Bitbucket repositories, Slack messages, and Microsoft 365 files. The ResearchAgent tool, which autonomously conducts web-based data collection, was identified as a key enabler of data exfiltration.

Attack Vector

Attackers could exploit this vulnerability by embedding a malicious link in an email or message. Once clicked, the injected prompt triggered Rovo to automatically retrieve and share sensitive information via the open web. Proof-of-concept demonstrations included the extraction of Confluence pages, Jira tickets, and SharePoint content containing personal data.

Response and Recommendations

Varonis reported the issue to Atlassian, which addressed the vulnerability prior to public disclosure. The researchers advised organizations to restrict Rovo’s access to critical systems, disable unused integrations, and isolate sensitive data domains such as legal, HR, and finance.

Atlassian’s Statement

A company representative stated that the vulnerability aligns with broader industry challenges in AI systems, similar to phishing attacks. They advised users to verify the authenticity of content shared with Atlassian applications and follow established security protocols.

Research and Conclusion

The research was presented at DEF CON 34, with a detailed technical analysis available on the Varonis blog. The findings highlight the growing risks associated with AI-driven tools and underscore the need for robust safeguards in enterprise environments.



About Author

en_USEnglish