Atlantis · Atlantis · CVE-2025-58445
**Name of the Vulnerable Software and Affected Versions**
Atlantis (affected versions not specified)
**Description**
Atlantis, a self-hosted golang application that listens for Terraform pull request events via webhooks, exposes detailed version information through the `/status` endpoint. This information disclosure could allow attackers to identify and target known issues associated with specific versions, potentially compromising the service's security.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.