Atlassian Rovo Flaw Lets Attackers Steal Jira and Confluence Data
Researchers have demonstrated that Atlassian's Rovo AI assistant can be manipulated through prompt injection to exfiltrate sensitive data from connected Jira and Confluence projects. The attack requires a user to interact with maliciously crafted content, potentially exposing confidential corporate information to external actors. Administrators should restrict Rovo access and monitor for unusual activity until a patch is available.