CVE-2021-21432
HIGHVela 0.7.0-0.7.4 - Unauthenticated Secret Exposure via .netrc File
Title source: llmDescription
Vela is a Pipeline Automation (CI/CD) framework built on Linux container technology written in Golang. An authentication mechanism added in version 0.7.0 enables some malicious user to obtain secrets utilizing the injected credentials within the `~/.netrc` file. Refer to the referenced GitHub Security Advisory for complete details. This is fixed in version 0.7.5.
References (5)
Core 5
Core References
Third Party Advisory x_refsource_confirm
https://github.com/go-vela/server/security/advisories/GHSA-8j3f-mhq8-gmh4
Release Notes, Third Party Advisory x_refsource_misc
https://pkg.go.dev/github.com/go-vela/server
Release Notes, Third Party Advisory x_refsource_misc
https://github.com/go-vela/server/releases/tag/v0.7.5
Patch, Third Party Advisory x_refsource_misc
https://github.com/go-vela/server/pull/337
Patch, Third Party Advisory x_refsource_misc
https://github.com/go-vela/server/commit/cb4352918b8ecace9fe969b90404d337b0744d46
Scores
CVSS v3
7.5
EPSS
0.0099
EPSS Percentile
57.8%
Attack Vector
ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:L
Details
CWE
CWE-285
CWE-862
Status
published
Products (2)
go-vela/server
0.7.0 - 0.7.5Go
go-vela/vela
< 0.7.5
Published
Apr 09, 2021
Tracked Since
Feb 18, 2026