CVE-2021-21432
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
09/04/2021
Last modified:
12/08/2022
Description
Vela is a Pipeline Automation (CI/CD) framework built on Linux container technology written in Golang. An authentication mechanism added in version 0.7.0 enables some malicious user to obtain secrets utilizing the injected credentials within the `~/.netrc` file. Refer to the referenced GitHub Security Advisory for complete details. This is fixed in version 0.7.5.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Base Score 2.0
3.50
Severity 2.0
LOW
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:go-vela:vela:*:*:*:*:*:*:*:* | 0.7.5 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



