DirectorySecurity Advisories
Sign In
Security Advisories

CGA-x5w5-gxv4-7j4p

Published

Last updated

https://images.chainguard.dev/security/CGA-x5w5-gxv4-7j4p
Package

atlantis-fips

Latest Update
Not affected
Aliases
  • CVE-2022-24912
  • GHSA-jxqv-jcvh-7gr4

Severity

7.5

High

CVSS V3

Summary

Atlantis Events vulnerable to Timing Attack

Description

The package github.com/runatlantis/atlantis/server/controllers/events before 0.19.7 is vulnerable to Timing Attack in the webhook event validator code, which does not use a constant-time comparison function to validate the webhook secret. It can allow an attacker to recover this secret as an attacker and then forge webhook events.

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images