VYPR

Atlantis

by Runatlantis

Source repositories

CVEs (5)

  • CVE-2024-52009CriNov 8, 2024
    risk 0.57cvss 9.8epss 0.01

    Atlantis is a self-hosted golang application that listens for Terraform pull request events via webhooks. Atlantis logs contains GitHub credentials (tokens `ghs_...`) when they are rotated. This enables an attacker able to read these logs to impersonate Atlantis application and…

  • CVE-2025-58445HigSep 6, 2025
    risk 0.49cvss 7.5epss 0.00

    Atlantis is a self-hosted golang application that listens for Terraform pull request events via webhooks. All versions of Atlantis publicly expose detailed version information through its /status endpoint. This information disclosure could allow attackers to identify and target…

  • CVE-2026-64679HigAug 21, 2026
    risk 0.46cvss 8.1epss 0.01

    Atlantis is a self-hosted golang application that listens for Terraform pull request events via webhooks. From 0.19.8 until 0.45.0, Atlantis does not consistently validate user-controlled workspace values supplied through accepted repository-level atlantis.yaml configuration or…

  • CVE-2026-82282HigAug 28, 2026
    risk 0.45cvss 8.0epss 0.00

    Atlantis through 0.47.1 fails to authenticate the /github-app/setup endpoint, allowing unauthenticated attackers to access GitHub App credentials. Attackers can observe or intercept the GitHub redirect during setup to obtain the RSA private key and webhook secret, enabling…

  • CVE-2022-24912HigJul 29, 2022
    risk 0.42cvss 7.5epss 0.01

    The package github.com/runatlantis/atlantis/server/controllers/events before 0.19.7 are vulnerable to Timing Attack in the webhook event validator code, which does not use a constant-time comparison function to validate the webhook secret. It can allow an attacker to recover…