6.9
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Description
Atlantis is a self-hosted golang application that listens for Terraform pull request events via webhooks. All versions of Atlantis publicly expose detailed version information through its /status endpoint. This information disclosure could allow attackers to identify and target known vulnerabilities associated with the specific versions, potentially compromising the service's security posture. This issue does not currently have a fix.
Basic Information
ID
CVE-2025-58445
Source
GitHub_M
Published
Sep 6, 2025 at 19:47
Affected Product
Vendor
runatlantis
Product
atlantis
Version
<= 0.35.1
Affected Versions
runatlantis atlantis <= 0.35.1