Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jxqv-jcvh-7gr4

Опубликовано: 30 июл. 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Atlantis Events vulnerable to Timing Attack

The package github.com/runatlantis/atlantis/server/controllers/events before 0.19.7 is vulnerable to Timing Attack in the webhook event validator code, which does not use a constant-time comparison function to validate the webhook secret. It can allow an attacker to recover this secret as an attacker and then forge webhook events.

Пакеты

Наименование

github.com/runatlantis/atlantis

go
Затронутые версииВерсия исправления

< 0.19.7

0.19.7

EPSS

Процентиль: 45%
0.00221
Низкий

7.5 High

CVSS3

Дефекты

CWE-203
CWE-208

Связанные уязвимости

CVSS3: 7.5
nvd
больше 3 лет назад

The package github.com/runatlantis/atlantis/server/controllers/events before 0.19.7 are vulnerable to Timing Attack in the webhook event validator code, which does not use a constant-time comparison function to validate the webhook secret. It can allow an attacker to recover this secret as an attacker and then forge webhook events.

EPSS

Процентиль: 45%
0.00221
Низкий

7.5 High

CVSS3

Дефекты

CWE-203
CWE-208