
Cloud Vulnerability DB
A community-led vulnerabilities database
Vela is a Pipeline Automation (CI/CD) framework built on Linux container technology written in Golang. In Vela compiler before version 0.6.1, there is a vulnerability which allows exposure of server configuration. It impacts all users of Vela. An attacker can use Sprig's env function to retrieve configuration information from the server (GitHub Advisory).
The vulnerability exists in the template functionality of the Vela pipeline. Using Sprig's env function in templates, attackers could access sensitive server configuration values like OAuth client IDs and server-worker communication secrets. For example, an attacker could create a malicious template that exposes sensitive values like VELA_SOURCE_CLIENT and VELA_SECRET (GitHub Advisory).
The vulnerability allows unauthorized access to sensitive server configuration data, including OAuth client IDs used for GitHub communication and secrets used for server-worker communication. This could potentially lead to further compromise of the Vela infrastructure (GitHub Advisory).
The vulnerability can be exploited by creating a malicious pipeline template that uses the Sprig env function to access server environment variables. No special privileges are required beyond the ability to create pipeline templates (GitHub Advisory).
The vulnerability has been patched in version 0.6.1. Users should upgrade to this version or later. Additionally, it is recommended to rotate all secrets after upgrading. There are no known workarounds for this vulnerability (GitHub Advisory, Vela Patch).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."