The package github.com/runatlantis/atlantis/server/controllers/events before 0.19.7 are vulnerable to Timing Attack in the webhook event validator code, which does not use a constant-time comparison function to validate the webhook secret. It can allow an attacker to recover this secret as an attacker and then forge webhook events.
CVSS
No CVSS.
References
Configurations
No configuration.
Information
Published : 2022-07-29 10:15
Updated : 2022-07-29 12:09
NVD link : CVE-2022-24912
Mitre link : CVE-2022-24912
JSON object : View
Products Affected
No product.
CWE
No CWE.
