<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 13:25:32 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-200833</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-200833</link>
      <description>EUVD-2026-200833</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-200833</guid>
    </item>
    <item>
      <title>fkie_cve-2024-52009</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-52009</link>
      <description>&lt;p&gt;Atlantis is a self-hosted golang application that listens for Terraform pull request events via webhooks. Atlantis logs contains GitHub credentials (tokens `ghs_...`) when they are rotated. This enables an attacker able to read these logs to impersonate Atlantis application and to perform actions on GitHub. When Atlantis is used to administer a GitHub organization, this enables getting administration privileges on the organization. This was reported in #4060 and fixed in #4667 . The fix was included in Atlantis v0.30.0. All users are advised to upgrade. There are no known workarounds for this vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Atlantis is a self-hosted golang application that listens for Terraform pull request events via webhooks. Atlantis logs contains GitHub credentials (tokens `ghs_...`) when they are rotated. This enables an attacker able to read these logs to impersonate Atlantis application and to perform actions on GitHub. When Atlantis is used to administer a GitHub organization, this enables getting administration privileges on the organization. This was reported in #4060 and fixed in #4667 . The fix was included in Atlantis v0.30.0. All users are advised to upgrade. There are no known workarounds for this vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-52009</guid>
    </item>
    <item>
      <title>GHSA-gppm-hq3p-h4rp — Git credentials are exposed in Atlantis logs</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-gppm-hq3p-h4rp</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/runatlantis/atlantis&lt;/p&gt;
&lt;p&gt;### Summary
_Short summary of the problem. Make the impact and severity as clear as possible. For example: An unsafe deserialization vulnerability allows any unauthenticated user to execute arbitrary code on the server._&lt;/p&gt;
&lt;p&gt;Atlantis logs contains GitHub credentials (tokens `ghs_...`) when they are rotated. This enables an attacker able to read these logs to impersonate Atlantis application and to perform actions on GitHub.&lt;/p&gt;
&lt;p&gt;When Atlantis is used to administer a GitHub organization, this enables getting administration privileges on the organization.&lt;/p&gt;
&lt;p&gt;This was reported in https://github.com/runatlantis/atlantis/issues/4060 and fixed in https://github.com/runatlantis/atlantis/pull/4667 . The fix was included in [Atlantis v0.30.0](https://github.com/runatlantis/atlantis/releases/tag/v0.30.0).&lt;/p&gt;
&lt;p&gt;### Details
_Give all details on the vulnerability. Pointing to the incriminated source code is very helpful for the maintainer._&lt;/p&gt;
&lt;p&gt;While auditing the Kubernetes/Argo CD/Atlantis deployment of some company, the following set-up was encountered:&lt;/p&gt;
&lt;p&gt;- Most employees have read-only access to Argo CD, enabling them to see the health of deployed applications.
- Atlantis was deployed as an Argo CD application.
- Atlantis was used to manage the configuration of a GitHub organization (such as team members), using [Terraform&amp;#39;s GitHub integration](https://registry.terraform.io/providers/integrations/github/latest).&lt;/p&gt;
&lt;p&gt;Atlantis logs on Argo CD contained lines such as:&lt;/p&gt;
&lt;p&gt;```json
{&amp;#34;level&amp;#34;:&amp;#34;debug&amp;#34;,&amp;#34;ts&amp;#34;:&amp;#34;2024-11…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/runatlantis/atlantis&lt;/p&gt;
&lt;p&gt;### Summary
_Short summary of the problem. Make the impact and severity as clear as possible. For example: An unsafe deserialization vulnerability allows any unauthenticated user to execute arbitrary code on the server._&lt;/p&gt;
&lt;p&gt;Atlantis logs contains GitHub credentials (tokens `ghs_...`) when they are rotated. This enables an attacker able to read these logs to impersonate Atlantis application and to perform actions on GitHub.&lt;/p&gt;
&lt;p&gt;When Atlantis is used to administer a GitHub organization, this enables getting administration privileges on the organization.&lt;/p&gt;
&lt;p&gt;This was reported in https://github.com/runatlantis/atlantis/issues/4060 and fixed in https://github.com/runatlantis/atlantis/pull/4667 . The fix was included in [Atlantis v0.30.0](https://github.com/runatlantis/atlantis/releases/tag/v0.30.0).&lt;/p&gt;
&lt;p&gt;### Details
_Give all details on the vulnerability. Pointing to the incriminated source code is very helpful for the maintainer._&lt;/p&gt;
&lt;p&gt;While auditing the Kubernetes/Argo CD/Atlantis deployment of some company, the following set-up was encountered:&lt;/p&gt;
&lt;p&gt;- Most employees have read-only access to Argo CD, enabling them to see the health of deployed applications.
- Atlantis was deployed as an Argo CD application.
- Atlantis was used to manage the configuration of a GitHub organization (such as team members), using [Terraform&amp;#39;s GitHub integration](https://registry.terraform.io/providers/integrations/github/latest).&lt;/p&gt;
&lt;p&gt;Atlantis logs on Argo CD contained lines such as:&lt;/p&gt;
&lt;p&gt;```json
{&amp;#34;level&amp;#34;:&amp;#34;debug&amp;#34;,&amp;#34;ts&amp;#34;:&amp;#34;2024-11…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-gppm-hq3p-h4rp</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:14515-1 — govulncheck-vulndb-0.0.20241120T172248-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:14515-1</link>
      <description>&lt;p&gt;govulncheck-vulndb-0.0.20241120T172248-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;govulncheck-vulndb-0.0.20241120T172248-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:14515-1</guid>
    </item>
  </channel>
</rss>
