<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T13:25:34.528535+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-200833</id>
    <title>EUVD-2026-200833</title>
    <updated>2026-10-05T13:25:34.532112+00:00</updated>
    <content>EUVD-2026-200833</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-200833"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-52009</id>
    <title>fkie_cve-2024-52009</title>
    <updated>2026-10-05T13:25:34.532166+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Atlantis is a self-hosted golang application that listens for Terraform pull request events via webhooks. Atlantis logs contains GitHub credentials (tokens `ghs_...`) when they are rotated. This enables an attacker able to read these logs to impersonate Atlantis application and to perform actions on GitHub. When Atlantis is used to administer a GitHub organization, this enables getting administration privileges on the organization. This was reported in #4060 and fixed in #4667 . The fix was included in Atlantis v0.30.0. All users are advised to upgrade. There are no known workarounds for this vulnerability.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-52009"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-gppm-hq3p-h4rp</id>
    <title>GHSA-gppm-hq3p-h4rp — Git credentials are exposed in Atlantis logs</title>
    <updated>2026-10-05T13:25:34.532228+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/runatlantis/atlantis</p>
<p>### Summary
_Short summary of the problem. Make the impact and severity as clear as possible. For example: An unsafe deserialization vulnerability allows any unauthenticated user to execute arbitrary code on the server._</p>
<p>Atlantis logs contains GitHub credentials (tokens `ghs_...`) when they are rotated. This enables an attacker able to read these logs to impersonate Atlantis application and to perform actions on GitHub.</p>
<p>When Atlantis is used to administer a GitHub organization, this enables getting administration privileges on the organization.</p>
<p>This was reported in https://github.com/runatlantis/atlantis/issues/4060 and fixed in https://github.com/runatlantis/atlantis/pull/4667 . The fix was included in [Atlantis v0.30.0](https://github.com/runatlantis/atlantis/releases/tag/v0.30.0).</p>
<p>### Details
_Give all details on the vulnerability. Pointing to the incriminated source code is very helpful for the maintainer._</p>
<p>While auditing the Kubernetes/Argo CD/Atlantis deployment of some company, the following set-up was encountered:</p>
<p>- Most employees have read-only access to Argo CD, enabling them to see the health of deployed applications.
- Atlantis was deployed as an Argo CD application.
- Atlantis was used to manage the configuration of a GitHub organization (such as team members), using [Terraform's GitHub integration](https://registry.terraform.io/providers/integrations/github/latest).</p>
<p>Atlantis logs on Argo CD contained lines such as:</p>
<p>```json
{"level":"debug","ts":"2024-11…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-gppm-hq3p-h4rp"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:14515-1</id>
    <title>openSUSE-SU-2024:14515-1 — govulncheck-vulndb-0.0.20241120T172248-1.1 on GA media</title>
    <updated>2026-10-05T13:25:34.532337+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>govulncheck-vulndb-0.0.20241120T172248-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:14515-1"/>
  </entry>
</feed>
