Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-jxqv-jcvh-7gr4: Atlantis Events prior to 0.19.7 vulnerable to Timing Attack

The package github.com/runatlantis/atlantis/server/controllers/events before 0.19.7 are vulnerable to Timing Attack in the webhook event validator code, which does not use a constant-time comparison function to validate the webhook secret. It can allow an attacker to recover this secret as an attacker and then forge webhook events.

ghsa
#web#git

Atlantis Events prior to 0.19.7 vulnerable to Timing Attack

High severity GitHub Reviewed Published Jul 30, 2022 • Updated Aug 6, 2022

Related news

CVE-2022-24912: Snyk Vulnerability Database | Snyk

The package github.com/runatlantis/atlantis/server/controllers/events before 0.19.7 are vulnerable to Timing Attack in the webhook event validator code, which does not use a constant-time comparison function to validate the webhook secret. It can allow an attacker to recover this secret as an attacker and then forge webhook events.