VYPR

apk package

chainguard/atlantis-fips

pkg:apk/chainguard/atlantis-fips

Vulnerabilities (62)

  • CVE-2023-44487HigKEVOct 10, 2023
    affected < 0.26.0-r3fixed 0.26.0-r3

    The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

  • CVE-2022-24912Jul 29, 2022
    affected < 0fixed 0

    The package github.com/runatlantis/atlantis/server/controllers/events before 0.19.7 are vulnerable to Timing Attack in the webhook event validator code, which does not use a constant-time comparison function to validate the webhook secret. It can allow an attacker to recover this

Page 4 of 4