VYPR
Vendor

Runatlantis

Products
1
CVEs
3
Across products
3
Status
Private

Products

1

Recent CVEs

3
  • CVE-2024-52009CriNov 8, 2024
    risk 0.57cvss 9.8epss 0.01

    Atlantis is a self-hosted golang application that listens for Terraform pull request events via webhooks. Atlantis logs contains GitHub credentials (tokens `ghs_...`) when they are rotated. This enables an attacker able to read these logs to impersonate Atlantis application and…

  • CVE-2025-58445HigSep 6, 2025
    risk 0.49cvss 7.5epss 0.00

    Atlantis is a self-hosted golang application that listens for Terraform pull request events via webhooks. All versions of Atlantis publicly expose detailed version information through its /status endpoint. This information disclosure could allow attackers to identify and target…

  • CVE-2022-24912HigJul 29, 2022
    risk 0.42cvss 7.5epss 0.01

    The package github.com/runatlantis/atlantis/server/controllers/events before 0.19.7 are vulnerable to Timing Attack in the webhook event validator code, which does not use a constant-time comparison function to validate the webhook secret. It can allow an attacker to recover…