Vulnerabilities > CVE-2021-21432 - Missing Authorization vulnerability in Go-Vela Vela

047910
CVSS 6.5 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
go-vela
CWE-862

Summary

Vela is a Pipeline Automation (CI/CD) framework built on Linux container technology written in Golang. An authentication mechanism added in version 0.7.0 enables some malicious user to obtain secrets utilizing the injected credentials within the `~/.netrc` file. Refer to the referenced GitHub Security Advisory for complete details. This is fixed in version 0.7.5.

Vulnerable Configurations

Part Description Count
Application
Go-Vela
1

Common Weakness Enumeration (CWE)