Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-3255 | Atlantis is a self-hosted golang application that listens for Terraform pull request events via webhooks. Atlantis logs contains GitHub credentials (tokens `ghs_...`) when they are rotated. This enables an attacker able to read these logs to impersonate Atlantis application and to perform actions on GitHub. When Atlantis is used to administer a GitHub organization, this enables getting administration privileges on the organization. This was reported in #4060 and fixed in #4667 . The fix was included in Atlantis v0.30.0. All users are advised to upgrade. There are no known workarounds for this vulnerability. |
Github GHSA |
GHSA-gppm-hq3p-h4rp | Git credentials are exposed in Atlantis logs |
Mon, 29 Sep 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:runatlantis:atlantis:*:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 12 Nov 2024 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 08 Nov 2024 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Atlantis is a self-hosted golang application that listens for Terraform pull request events via webhooks. Atlantis logs contains GitHub credentials (tokens `ghs_...`) when they are rotated. This enables an attacker able to read these logs to impersonate Atlantis application and to perform actions on GitHub. When Atlantis is used to administer a GitHub organization, this enables getting administration privileges on the organization. This was reported in #4060 and fixed in #4667 . The fix was included in Atlantis v0.30.0. All users are advised to upgrade. There are no known workarounds for this vulnerability. | |
| Title | Git credentials are exposed in atlantis logs | |
| Weaknesses | CWE-532 | |
| References |
|
|
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-11-12T19:19:58.293Z
Reserved: 2024-11-04T17:46:16.779Z
Link: CVE-2024-52009
Updated: 2024-11-12T19:19:53.335Z
Status : Analyzed
Published: 2024-11-08T23:15:05.030
Modified: 2025-09-29T15:06:51.653
Link: CVE-2024-52009
No data.
OpenCVE Enrichment
Updated: 2025-07-13T11:31:55Z
EUVD
Github GHSA