{"id":"GHSA-jxqv-jcvh-7gr4","summary":"Atlantis Events vulnerable to Timing Attack","details":"The package github.com/runatlantis/atlantis/server/controllers/events before 0.19.7 is vulnerable to Timing Attack in the webhook event validator code, which does not use a constant-time comparison function to validate the webhook secret. It can allow an attacker to recover this secret as an attacker and then forge webhook events.","aliases":["CVE-2022-24912","GO-2022-0534"],"modified":"2026-02-04T03:16:36.500682Z","published":"2022-07-30T00:00:41Z","related":["CGA-3g96-mh6f-w247"],"database_specific":{"cwe_ids":["CWE-203","CWE-208"],"github_reviewed_at":"2022-08-06T05:21:43Z","github_reviewed":true,"nvd_published_at":"2022-07-29T10:15:00Z","severity":"HIGH"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-24912"},{"type":"WEB","url":"https://github.com/runatlantis/atlantis/issues/2391"},{"type":"WEB","url":"https://github.com/runatlantis/atlantis/pull/2392"},{"type":"WEB","url":"https://github.com/runatlantis/atlantis/commit/48870911974adddaa4c99c8089e79b7d787fa820"},{"type":"PACKAGE","url":"https://github.com/runatlantis/atlantis"},{"type":"WEB","url":"https://pkg.go.dev/vuln/GO-2022-0534"},{"type":"WEB","url":"https://security.snyk.io/vuln/SNYK-GOLANG-GITHUBCOMRUNATLANTISATLANTISSERVERCONTROLLERSEVENTS-2950851"}],"affected":[{"package":{"name":"github.com/runatlantis/atlantis","ecosystem":"Go","purl":"pkg:golang/github.com/runatlantis/atlantis"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.19.7"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/07/GHSA-jxqv-jcvh-7gr4/GHSA-jxqv-jcvh-7gr4.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}