Atlassian Rovo Exfiltrates Data, Bypassing Controls

(promptarmor.com)

52 points | by hackerBanana 2 hours ago

6 comments

  • pram 49 minutes ago
    I can’t get over how bad “Rovo” is. Somehow more aggressive and useless than Microsoft putting “Copilot” everywhere.

    It’s objectively worse than using something like Cowork + MCP, AND they injected it into every single page on JIRA and Confluent which has made web browsing way slower while all the junk is loading.

    • jerf 23 minutes ago
      Rovo has my favorite example of AI misfeature. Just checked, it's still there in Cloud Confluence. In Edit mode for a page, you can select a range of text and a menu will pop up, with Ask Rovo being a drop down on it. There's a few good options... Improve Formatting, translation options, Make Shorter...

      ... but it also has Make Longer. Yes, a built-in feature to type some text in, and the use the mighty power of AI to bloat it.

      Naturally, you can repeat this process several times on the same text, for your own little personal demonstration of what model collapse looks like in real time.

    • verdverm 28 minutes ago
      Have you seen the markdown agent instructions they provide in their new agentic `twg` cli? 70k tokens one average, there are more than one...

      Rovo is the worse Ai I have used, I suggested they stop trying and let us have model choice. Save money and don't do things out of their skill sets

  • john_strinlai 49 minutes ago
    ~every ai vulnerability write up boils down to "just ask it do to the thing", but with fancier terms like "indirect prompt injection".
  • consp 38 minutes ago
    It's nice they force rovo now for document/version diff's. Because you need to burn down the rainforest for those. (sarcasm ... for obvious reasons)
  • formerly_proven 1 hour ago
    > Rovo's URL retrieval tool is insecure: there are no protections against opening a URL that has been dynamically created by the agent. Here, Rovo is manipulated to append sensitive data to an attacker's URL. When Rovo calls the insecure tool to open the URL, the attacker's site logs the request, including the appended sensitive data.
  • khanan 56 minutes ago
    Atlassian has gone from a trusted enterprise-partner to a complete shit-show in just 18 months. This surprises nobody. There will be classes taught in how to fuck up a good business and Atlassian will be the prime example.

    Regards, /someone who migrated 3500 users from Atlassians products recently due to their "cloud only"-bullshit.

    • yborg 36 minutes ago
      You'd have to look at their profit numbers. They have a huge captive base of customers, like Adobe it might take decades for things to get bad enough and alternatives to arise before their profitability is impacted. And the executives who benefit will have cashed out long before then.
      • walrus01 21 minutes ago
        Recently saw an example of somebody who vibe coded a tool to mass export the contents of a 'Confluence' wiki into an instance of self hosted mediawiki, preserving everything.

        Mediawiki as a whole has a feature set that 95% of organizations will only scratch the surface of. There's a ridiculous number of possible plugins and customization if you have somebody who knows what they're doing with it.

        The majority of companies that need an internal KB/wiki do not have as complex needs or use cases as wikipedia itself or the wikimedia foundation.

    • gbalduzzi 42 minutes ago
      I started to consider it a show show way earlier than 18 months ago. Jira is so terrible to use that it is hard to phantom how they are able to be paid for their product
      • mosura 24 minutes ago
        Jira is how it is because almost any product that grows to be that flexible will develop the same problems.

        They failed to rearchitect it to something suitable for the inherent flexibility though, so it remains a disaster area, but one that is uniquely able to fit the whims of any manager that can then mandate it for everyone else.