{"id":"CVE-2022-24912","aliases":["GHSA-jxqv-jcvh-7gr4","GO-2022-0534"],"url":"https://o3.security/vulnerability/CVE-2022-24912","summary":"Timing Attack","details":"The package github.com/runatlantis/atlantis/server/controllers/events before 0.19.7 are vulnerable to Timing Attack in the webhook event validator code, which does not use a constant-time comparison function to validate the webhook secret. It can allow an attacker to recover this secret as an attacker and then forge webhook events.","published":"2022-07-29T10:00:15.439Z","modified":"2026-07-15T01:48:55.668802882Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":2,"affectedPackages":[{"ecosystem":"Go","name":"github.com/runatlantis/atlantis","fixedVersion":"0.19.7"}],"fix":{"url":"https://github.com/runatlantis/atlantis/commit/48870911974adddaa4c99c8089e79b7d787fa820","label":"runatlantis/atlantis@4887091"},"references":[{"type":"WEB","url":"https://security.snyk.io/vuln/SNYK-GOLANG-GITHUBCOMRUNATLANTISATLANTISSERVERCONTROLLERSEVENTS-2950851"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/24xxx/CVE-2022-24912.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-24912"},{"type":"REPORT","url":"https://github.com/runatlantis/atlantis/issues/2391"},{"type":"FIX","url":"https://github.com/runatlantis/atlantis/commit/48870911974adddaa4c99c8089e79b7d787fa820"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:48:55.668802882Z"}}