The injection manipulates Rovo to taxable Jira tickets and Confluence documents to the attacker’s website
Rovo's URL retrieval instrumentality is insecure: there are nary protections against opening a URL that has been dynamically created by the agent. Here, Rovo is manipulated to append delicate information to an attacker's URL. When Rovo calls the insecure instrumentality to unfastened the URL, the attacker's tract logs the request, including the appended delicate data.
Note: This onslaught succeeds moreover if an statement has abnormal web hunt for Rovo. This is because the web hunt mounting fails to region the instrumentality for opening the hunt results.
If the personification returns to the chat later, they spot the agent's suggested summons updates, but nary grounds of the attack.
English (US) ·
Indonesian (ID) ·