PT-2024-35093 · Atlantis · Atlantis

Niooss-Ledger

·

Published

2024-11-08

·

Updated

2024-11-21

·

CVE-2024-52009

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Atlantis versions prior to 0.30.0
Description The issue concerns the exposure of GitHub credentials in Atlantis logs, specifically tokens starting with ghs ..., when they are rotated. This allows an attacker who can read these logs to impersonate the Atlantis application and perform actions on GitHub, potentially gaining administration privileges on a GitHub organization if Atlantis is used for administration. The problem was reported and fixed, with the fix included in Atlantis v0.30.0.
Recommendations For versions prior to 0.30.0, upgrade to Atlantis v0.30.0 to resolve the issue. As a temporary workaround, consider restricting access to the Atlantis logs to minimize the risk of credential exposure. Additionally, review and limit the privileges assigned to the GitHub credentials used by Atlantis to reduce the potential impact of impersonation.

Exploit

Fix

Insertion into Log File

Weakness Enumeration

Related Identifiers

CVE-2024-52009
GHSA-GPPM-HQ3P-H4RP
GO-2024-3265
OPENSUSE-SU-2024:14515-1

Affected Products

Atlantis