Atlantis is a self-hosted golang application that listens for Terraform pull request events via webhooks. All versions of Atlantis publicly expose detailed version information through its /status endpoint. This information disclosure could allow attackers to identify and target known vulnerabilities associated with the specific versions, potentially compromising the service's security posture. This issue does not currently have a fix.
History

Sat, 06 Sep 2025 20:00:00 +0000

Type Values Removed Values Added
Description Atlantis is a self-hosted golang application that listens for Terraform pull request events via webhooks. All versions of Atlantis publicly expose detailed version information through its /status endpoint. This information disclosure could allow attackers to identify and target known vulnerabilities associated with the specific versions, potentially compromising the service's security posture. This issue does not currently have a fix.
Title Atlantis Exposes Service Version Publicly on /status API Endpoint
Weaknesses CWE-200
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-09-06T19:47:33.669Z

Reserved: 2025-09-01T20:03:06.533Z

Link: CVE-2025-58445

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-09-06T20:15:30.130

Modified: 2025-09-06T20:15:30.130

Link: CVE-2025-58445

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.