SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-26294

In Vela compiler before version 0.6.1 there is a vulnerability which allows exposure of server configuration.

MEDIUM 5.3EPSS 1.78%

Does this matter?

Lower severity and a low EPSS score (1.78%). Track it; it rarely justifies an emergency change on its own.

Description

Vela is a Pipeline Automation (CI/CD) framework built on Linux container technology written in Golang. In Vela compiler before version 0.6.1 there is a vulnerability which allows exposure of server configuration. It impacts all users of Vela. An attacker can use Sprig's `env` function to retrieve configuration information, see referenced GHSA for an example. This has been fixed in version 0.6.1. In addition to upgrading, it is recommended to rotate all secrets.

CVSS 3.1
5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS
1.78% probability · 77th percentile
CISA KEV
Not listed
Weakness
CWE-78
Affected
target/compiler
Source
security-advisories@github.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.