PT-2024-35093 · Atlantis · Atlantis
Niooss-Ledger
·
Published
2024-11-08
·
Updated
2024-11-21
·
CVE-2024-52009
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Atlantis versions prior to 0.30.0
Description
The issue concerns the exposure of GitHub credentials in Atlantis logs, specifically tokens starting with
ghs ..., when they are rotated. This allows an attacker who can read these logs to impersonate the Atlantis application and perform actions on GitHub, potentially gaining administration privileges on a GitHub organization if Atlantis is used for administration. The problem was reported and fixed, with the fix included in Atlantis v0.30.0.Recommendations
For versions prior to 0.30.0, upgrade to Atlantis v0.30.0 to resolve the issue. As a temporary workaround, consider restricting access to the Atlantis logs to minimize the risk of credential exposure. Additionally, review and limit the privileges assigned to the GitHub credentials used by Atlantis to reduce the potential impact of impersonation.
Exploit
Fix
Insertion into Log File
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Atlantis