CVE Vulnerabilities

CVE-2024-52009

Insertion of Sensitive Information into Log File

Published: Nov 08, 2024 | Modified: Sep 29, 2025
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Atlantis is a self-hosted golang application that listens for Terraform pull request events via webhooks. Atlantis logs contains GitHub credentials (tokens ghs_...) when they are rotated. This enables an attacker able to read these logs to impersonate Atlantis application and to perform actions on GitHub. When Atlantis is used to administer a GitHub organization, this enables getting administration privileges on the organization. This was reported in #4060 and fixed in #4667 . The fix was included in Atlantis v0.30.0. All users are advised to upgrade. There are no known workarounds for this vulnerability.

Weakness

The product writes sensitive information to a log file.

Affected Software

Name Vendor Start Version End Version
Atlantis Runatlantis * 0.30.0 (excluding)

Potential Mitigations

References