CVE 6.9 MEDIUM

Atlantis Exposes Service Version Publicly on /status API Endpoint_CVE-2025-58445

6.9 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

Description

Atlantis is a self-hosted golang application that listens for Terraform pull request events via webhooks. All versions of Atlantis publicly expose detailed version information through its /status endpoint. This information disclosure could allow attackers to identify and target known vulnerabilities associated with the specific versions, potentially compromising the service's security posture. This issue does not currently have a fix.

Basic Information

ID CVE-2025-58445
Source GitHub_M
Published Sep 6, 2025 at 19:47

Affected Product

Vendor runatlantis
Product atlantis
Version <= 0.35.1
Affected Versions runatlantis atlantis <= 0.35.1

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.