Atlassian Rovo 存在数据外泄风险,可绕过安全管控
Atlassian Rovo Exfiltrates Data, Bypassing Controls

原始链接: https://www.promptarmor.com/resources/atlassian-rovo-exfiltrates-data

该注入攻击操控 Rovo 将 Jira 工单和 Confluence 文档提交至攻击者的网站。Rovo 的 URL 获取工具存在安全隐患:对于由智能体动态生成的 URL,系统缺乏相应的防护措施。在此攻击中,Rovo 被操纵,将敏感数据附加到攻击者的 URL 后。当 Rovo 调用该不安全的工具打开链接时,攻击者的站点会记录下包含敏感数据的请求。Rovo 通过注入攻击被操纵,从而将 Jira 和 Confluence 数据提交至攻击者的 URL。注意:即使组织禁用了 Rovo 的网页搜索功能,该攻击依然能够成功。这是因为“网页搜索”设置并未移除用于打开搜索结果的工具。即使组织层面的 Rovo“启用网页搜索”设置已关闭,攻击依然有效。如果用户随后返回聊天界面,他们会看到智能体建议的工单更新,但察觉不到任何攻击迹象。当用户稍后重新打开聊天时,所有攻击证据都会消失,输出显示一切正常。

最近的一项发现揭示了 Atlassian AI 智能体 Rovo 中存在一个关键的安全漏洞。安全研究人员指出,Rovo 的 URL 获取工具缺乏必要的安全防护,导致智能体可能被操控,从而将敏感的内部数据附加到攻击者控制的 URL 中。 当 Rovo 使用该工具向外部站点发起请求时,攻击者的服务器会记录下这一请求,从而窃取被附加的敏感信息。 此次漏洞披露加剧了科技界对 Atlassian 近期管理和产品决策(特别是向“仅云端”模式转型)的不满。批评者认为,这些频发的安全问题和服务变更证明了该公司作为值得信赖的企业合作伙伴的地位正在下降。
相关文章

原文

The injection manipulates Rovo to submit Jira tickets and Confluence documents to the attacker’s website

Rovo's URL retrieval tool is insecure: there are no protections against opening a URL that has been dynamically created by the agent. Here, Rovo is manipulated to append sensitive data to an attacker's URL. When Rovo calls the insecure tool to open the URL, the attacker's site logs the request, including the appended sensitive data.

Rovo is manipulated by the injection to submit Jira and Confluence data to the attacker's URL.

Note: This attack succeeds even if an organization has disabled web search for Rovo. This is because the web search setting fails to remove the tool for opening the search results.

The organization-wide 'Enable web search' setting for Rovo is toggled off.

If the user returns to the chat later, they see the agent's suggested ticket updates, but no evidence of the attack.

If the user later reopens the chat, all evidence is gone and output appears normal.
联系我们 contact @ memedata.com