CVE Database
/

CVE-2025-58445

Back to search

CVE-2025-58445

Published: Sep 6, 2025

Modified: Sep 8, 2025

PUBLISHED

Description

Atlantis is a self-hosted golang application that listens for Terraform pull request events via webhooks. All versions of Atlantis publicly expose detailed version information through its /status endpoint. This information disclosure could allow attackers to identify and target known vulnerabilities associated with the specific versions, potentially compromising the service's security posture. This issue does not currently have a fix.

VendorProductVersions

runatlantis

atlantis

affected
<= 0.35.1

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now
CVE-2025-58445 - Security Vulnerability | QwikSec