Back

MEDIUM

Atlantis Exposes Service Version Publicly on /status API Endpoint

Published Sep 6, 2025

Description

Atlantis is a self-hosted golang application that listens for Terraform pull request events via webhooks. All versions of Atlantis publicly expose detailed version information through its /status endpoint. This information disclosure could allow attackers to identify and target known vulnerabilities associated with the specific versions, potentially compromising the service's security posture. This issue does not currently have a fix.

Affected products

Remediation

No remediation recorded yet.

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Sep 6, 2025
Updated Sep 8, 2025
Reserved Sep 1, 2025
CISA Vulnrichment
Updated Sep 8, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner GitHub_M
Published Sep 6, 2025
Updated Sep 8, 2025
Exploited since n/a
EUVD-2025-27088 GHSA-XH7V-965R-23F7