Описание
Atlantis is a self-hosted golang application that listens for Terraform pull request events via webhooks. All versions of Atlantis publicly expose detailed version information through its /status endpoint. This information disclosure could allow attackers to identify and target known vulnerabilities associated with the specific versions, potentially compromising the service's security posture. This issue does not currently have a fix.
Ссылки
- ExploitVendor Advisory
- ExploitVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 0.35.1 (включая)
cpe:2.3:a:runatlantis:atlantis:*:*:*:*:*:*:*:*
EPSS
Процентиль: 17%
0.00056
Низкий
7.5 High
CVSS3
Дефекты
CWE-200
NVD-CWE-noinfo
Связанные уязвимости
CVSS3: 7.5
github
5 месяцев назад
Atlantis Exposes Service Version Publicly on /status API Endpoint
EPSS
Процентиль: 17%
0.00056
Низкий
7.5 High
CVSS3
Дефекты
CWE-200
NVD-CWE-noinfo