Vulnerability Report: GO-2024-3265
- CVE-2024-52009, GHSA-gppm-hq3p-h4rp
- Affects: github.com/runatlantis/atlantis
- Published: Nov 20, 2024
- Modified: Dec 12, 2024
Git credentials are exposed in Atlantis logs in github.com/runatlantis/atlantis
For detailed information about this vulnerability, visit https://github.com/runatlantis/atlantis/security/advisories/GHSA-gppm-hq3p-h4rp.
Affected Packages
-
PathGo VersionsSymbols
-
before v0.30.0
3 unexported affected symbols
- githubAppTokenRotator.GenerateJob
- githubAppTokenRotator.Run
- githubAppTokenRotator.rotate
Aliases
References
- https://github.com/runatlantis/atlantis/security/advisories/GHSA-gppm-hq3p-h4rp
- https://github.com/runatlantis/atlantis/commit/0def7d3fb74aabb75570554692b053950cde02e1
- https://github.com/runatlantis/atlantis/pull/4667
- https://github.com/runatlantis/atlantis/issues/4060
- https://argo-cd.readthedocs.io/en/stable/operator-manual/security
- https://github.com/runatlantis/atlantis/releases/tag/v0.30.0
- https://vuln.go.dev/ID/GO-2024-3265.json
Feedback
See anything missing or incorrect?
Suggest an edit to this report.