Atlantis is a self-hosted golang application that listens for Terraform pull request events via webhooks. All versions of Atlantis publicly expose detailed version information through its /status endpoint. This information disclosure could allow attackers to identify and target known vulnerabilities associated with the specific versions, potentially compromising the service's security posture. This issue does not currently have a fix.
References
Link | Resource |
---|---|
https://github.com/runatlantis/atlantis/security/advisories/GHSA-xh7v-965r-23f7 | Exploit Vendor Advisory |
https://github.com/runatlantis/atlantis/security/advisories/GHSA-xh7v-965r-23f7 | Exploit Vendor Advisory |
Configurations
History
10 Sep 2025, 19:43
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/runatlantis/atlantis/security/advisories/GHSA-xh7v-965r-23f7 - Exploit, Vendor Advisory | |
First Time |
Runatlantis atlantis
Runatlantis |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
CWE | NVD-CWE-noinfo | |
CPE | cpe:2.3:a:runatlantis:atlantis:*:*:*:*:*:*:*:* |
08 Sep 2025, 15:15
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/runatlantis/atlantis/security/advisories/GHSA-xh7v-965r-23f7 - |
06 Sep 2025, 20:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-09-06 20:15
Updated : 2025-09-10 19:43
NVD link : CVE-2025-58445
Mitre link : CVE-2025-58445
CVE.ORG link : CVE-2025-58445
JSON object : View
Products Affected
runatlantis
- atlantis
CWE