HIGH7.5
GHSA-jxqv-jcvh-7gr4
Atlantis Events vulnerable to Timing Attack
Quick fix
GHSA-jxqv-jcvh-7gr4 — github.com/runatlantis/atlantis: upgrade to the fixed version with the command below.
go get github.com/runatlantis/atlantis@v0.19.7Details
The package github.com/runatlantis/atlantis/server/controllers/events before 0.19.7 is vulnerable to Timing Attack in the webhook event validator code, which does not use a constant-time comparison function to validate the webhook secret. It can allow an attacker to recover this secret as an attacker and then forge webhook events.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/runatlantis/atlantis
Introduced in:
0Fixed in: 0.19.7Fix
go get github.com/runatlantis/atlantis@v0.19.7References
- https://nvd.nist.gov/vuln/detail/CVE-2022-24912[ADVISORY]
- https://github.com/runatlantis/atlantis/issues/2391[WEB]
- https://github.com/runatlantis/atlantis/pull/2392[WEB]
- https://github.com/runatlantis/atlantis/commit/48870911974adddaa4c99c8089e79b7d787fa820[WEB]
- https://github.com/runatlantis/atlantis[PACKAGE]
- https://pkg.go.dev/vuln/GO-2022-0534[WEB]
- https://security.snyk.io/vuln/SNYK-GOLANG-GITHUBCOMRUNATLANTISATLANTISSERVERCONTROLLERSEVENTS-2950851[WEB]