VDB
Sign up
HIGH7.5

GHSA-jxqv-jcvh-7gr4

Atlantis Events vulnerable to Timing Attack

Quick fix

GHSA-jxqv-jcvh-7gr4 — github.com/runatlantis/atlantis: upgrade to the fixed version with the command below.

go get github.com/runatlantis/atlantis@v0.19.7

Details

The package github.com/runatlantis/atlantis/server/controllers/events before 0.19.7 is vulnerable to Timing Attack in the webhook event validator code, which does not use a constant-time comparison function to validate the webhook secret. It can allow an attacker to recover this secret as an attacker and then forge webhook events.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/runatlantis/atlantis
Introduced in: 0Fixed in: 0.19.7
Fixgo get github.com/runatlantis/atlantis@v0.19.7

References