Runatlantis

Atlantis

5 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.26%
  • Veröffentlicht 28.08.2026 16:19:01
  • Zuletzt bearbeitet 24.09.2026 20:43:32

Atlantis through 0.47.1 fails to authenticate the /github-app/setup endpoint, allowing unauthenticated attackers to access GitHub App credentials. Attackers can observe or intercept the GitHub redirect during setup to obtain the RSA private key and w...

  • EPSS 0.38%
  • Veröffentlicht 21.08.2026 21:17:01
  • Zuletzt bearbeitet 09.09.2026 21:06:39

Atlantis is a self-hosted golang application that listens for Terraform pull request events via webhooks. From 0.19.8 until 0.45.0, Atlantis does not consistently validate user-controlled workspace values supplied through accepted repository-level at...

Exploit
  • EPSS 0.46%
  • Veröffentlicht 06.09.2025 19:47:33
  • Zuletzt bearbeitet 10.09.2025 19:43:08

Atlantis is a self-hosted golang application that listens for Terraform pull request events via webhooks. All versions of Atlantis publicly expose detailed version information through its /status endpoint. This information disclosure could allow atta...

Exploit
  • EPSS 0.72%
  • Veröffentlicht 08.11.2024 23:15:05
  • Zuletzt bearbeitet 29.09.2025 15:06:51

Atlantis is a self-hosted golang application that listens for Terraform pull request events via webhooks. Atlantis logs contains GitHub credentials (tokens `ghs_...`) when they are rotated. This enables an attacker able to read these logs to imperson...

Exploit
  • EPSS 1.16%
  • Veröffentlicht 29.07.2022 10:15:12
  • Zuletzt bearbeitet 21.11.2024 06:51:22

The package github.com/runatlantis/atlantis/server/controllers/events before 0.19.7 are vulnerable to Timing Attack in the webhook event validator code, which does not use a constant-time comparison function to validate the webhook secret. It can all...