Data-Sculptor CSV expression evaluation leads to backend RCE, Kubernetes serviceaccount token disclosure, and authenticated Kubernetes control-plane access

Disclosed by
MononcleMich
  • Engagement Atlassian
  • Disclosed date about 2 months ago
  • Points 20
  • Priority P2 Bugcrowd's VRT priority rating
  • Status Resolved This vulnerability has been accepted and fixed
Summary by Atlassian

Server-side Injection RCE Vulnerability in Rovo

Summary by MononcleMich

An authenticated user with access to Atlassian Rovo could cause attacker-controlled code to be executed by Rovo inside an Atlassian backend runtime.

From the same execution path, a live secret could be accessed that could be used to pivot to backend systems.

Atlassian assessed the issue as a CVSS 7.8/High and has resolved the vulnerability.

Activity