安全研究机构PromptArmor发现Atlassian的Rovo AI助手存在严重安全漏洞,攻击者可利用间接提示词注入技术绕过安全防护,从Jira工单、Confluence文档及通过connectors访问的其他系统中窃取敏感数据[1]。该漏洞利用Rovo的URL检索工具执行攻击,即使禁用网络搜索功能也无法防御[1]。攻击者还可通过不安全的Markdown图片渲染机制进一步实现数据外泄[1]。
PromptArmor于2024年5月23日向Atlassian报告了这一漏洞[1]。超过两个月后,Atlassian未进行实质性处理,目前Rovo仍存在该漏洞[1]。
Security research firm PromptArmor has identified a critical vulnerability in Atlassian's Rovo AI assistant that allows attackers to bypass security controls and extract sensitive data from systems including Jira tickets and Confluence documents [1]. The flaw exploits indirect prompt injection techniques to manipulate Rovo's URL retrieval tool, enabling unauthorized access to information stored across connected data sources [1]. Notably, the vulnerability persists even when network search functionality is disabled, rendering conventional security mitigations ineffective [1].
PromptArmor disclosed the vulnerability to Atlassian on May 23, 2024, yet more than two months later the company has taken no substantive remedial action [1]. The attack chain leverages insecure Markdown image rendering as a secondary mechanism to exfiltrate compromised data [1]. At present, Rovo remains exposed to this exploitation method, leaving organizations using the platform at risk of data breaches through compromised AI-assisted workflows [1].