Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2021-21432

Vela is a Pipeline Automation (CI/CD) framework built on Linux container technology written in Golang. An authentication mechanism added in version 0.7.0 enables some malicious user to obtain secrets utilizing the injected credentials within the `~/.netrc` file. Refer to the referenced GitHub Security Advisory for complete details. This is fixed in version 0.7.5.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 53.0%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 3.5
Products affected by CVE-2021-21432
  • Go-Vela » Vela » Version: Any
    cpe:2.3:a:go-vela:vela:*


Contact Us

Shodan ® - All rights reserved