Summary by Atlassian
Server-side Injection RCE Vulnerability in Rovo
Server-side Injection RCE Vulnerability in Rovo
An authenticated user with access to Atlassian Rovo could cause attacker-controlled code to be executed by Rovo inside an Atlassian backend runtime.
From the same execution path, a live secret could be accessed that could be used to pivot to backend systems.
Atlassian assessed the issue as a CVSS 7.8/High and has resolved the vulnerability.