Hi all,
While adopting Rovo, has any of your Cybersec teams conducted Penetration testing? Have they identified any issues like Prompt Injection or Sensitive Information Disclosure?
We have seen these identified in one of our very secure Cloud Enterprise org and I'd like to find what solution was applied to overcome this. Any help appreciated.
Atlassian has its own place for reporting the vulnerabilities upon the penetration testing. You would need to report this vulnerability, they need to verify it and upon that, they would apply a fix.
You can report that in here: https://www.atlassian.com/trust/security/report-a-vulnerability
They also have a bug bounty program that is hosted by Bugcrowd where the report could also be reported.
OffensiveSecurity has a good article on this: https://www.offsec.com/blog/how-to-prevent-prompt-injection/
Thank you @Nikola Perisic This has been reported to Atlassian and they are involved with the Security team in understanding further details. We have investigated the permissions and the system is quite restricted in itself. So must be something else causing in the underlying LLM layer.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
@Anandhi Arumugam _Cprime_ One distinction may help your investigation: prompt injection or sensitive-data disclosure doesn’t necessarily point to the underlying LLM. Rovo retrieves authorized organizational data and can use tools/actions around the model, so findings can occur in retrieval, context handling, tool execution, output handling, or permissions enforcement. I’d document the exact attack path with your security team and Atlassian—it will help identify which control actually failed.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Awesome! Keep us updated, if you would.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.