DirectorySecurity Advisories
Sign In
Security Advisories

CGA-4j9q-52f5-f8r4

Published

Last updated

https://images.chainguard.dev/security/CGA-4j9q-52f5-f8r4
Package

atlantis

Latest Update
Not affected
Aliases
  • CVE-2022-24912
  • GHSA-jxqv-jcvh-7gr4

Severity

7.5

High

CVSS V3

Summary

Atlantis Events vulnerable to Timing Attack

Description

The package github.com/runatlantis/atlantis/server/controllers/events before 0.19.7 is vulnerable to Timing Attack in the webhook event validator code, which does not use a constant-time comparison function to validate the webhook secret. It can allow an attacker to recover this secret as an attacker and then forge webhook events.

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images