PT-2021-11235 · Unknown+2 · Vela Compiler+2

Matt-Fevold

+1

·

Published

2021-01-04

·

Updated

2024-08-21

·

CVE-2020-26294

CVSS v3.1

7.4

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Vela versions prior to 0.6.1 Vela compiler versions prior to 0.6.1
Description: The issue allows exposure of server configuration, impacting all users of Vela. An attacker can use Sprig's env function to retrieve configuration information. This can be done via pipeline template functionality. For example, using the env function in a template to echo sensitive information such as VELA SOURCE CLIENT or VELA SECRET.
Recommendations: For versions prior to 0.6.1, upgrade to version 0.6.1. Rotate all secrets to minimize the risk of exploitation. As a temporary workaround, consider restricting the use of Sprig's env function in pipeline templates until the issue is resolved.

Exploit

Fix

Information Disclosure

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2020-26294
GHSA-GV2H-GF8M-R68J
GO-2022-0838

Affected Products

Sprig
Vela
Vela Compiler