CVE-2026-82282
- EPSS 0.26%
- Veröffentlicht 28.08.2026 16:19:01
- Zuletzt bearbeitet 24.09.2026 20:43:32
Atlantis through 0.47.1 fails to authenticate the /github-app/setup endpoint, allowing unauthenticated attackers to access GitHub App credentials. Attackers can observe or intercept the GitHub redirect during setup to obtain the RSA private key and w...
CVE-2026-64679
- EPSS 0.38%
- Veröffentlicht 21.08.2026 21:17:01
- Zuletzt bearbeitet 09.09.2026 21:06:39
Atlantis is a self-hosted golang application that listens for Terraform pull request events via webhooks. From 0.19.8 until 0.45.0, Atlantis does not consistently validate user-controlled workspace values supplied through accepted repository-level at...
CVE-2025-58445
- EPSS 0.46%
- Veröffentlicht 06.09.2025 19:47:33
- Zuletzt bearbeitet 10.09.2025 19:43:08
Atlantis is a self-hosted golang application that listens for Terraform pull request events via webhooks. All versions of Atlantis publicly expose detailed version information through its /status endpoint. This information disclosure could allow atta...
CVE-2024-52009
- EPSS 0.72%
- Veröffentlicht 08.11.2024 23:15:05
- Zuletzt bearbeitet 29.09.2025 15:06:51
Atlantis is a self-hosted golang application that listens for Terraform pull request events via webhooks. Atlantis logs contains GitHub credentials (tokens `ghs_...`) when they are rotated. This enables an attacker able to read these logs to imperson...
CVE-2022-24912
- EPSS 1.16%
- Veröffentlicht 29.07.2022 10:15:12
- Zuletzt bearbeitet 21.11.2024 06:51:22
The package github.com/runatlantis/atlantis/server/controllers/events before 0.19.7 are vulnerable to Timing Attack in the webhook event validator code, which does not use a constant-time comparison function to validate the webhook secret. It can all...