CVE-2020-26294
vulnerability analysis and mitigation

Overview

Vela is a Pipeline Automation (CI/CD) framework built on Linux container technology written in Golang. In Vela compiler before version 0.6.1, there is a vulnerability which allows exposure of server configuration. It impacts all users of Vela. An attacker can use Sprig's env function to retrieve configuration information from the server (GitHub Advisory).

Technical details

The vulnerability exists in the template functionality of the Vela pipeline. Using Sprig's env function in templates, attackers could access sensitive server configuration values like OAuth client IDs and server-worker communication secrets. For example, an attacker could create a malicious template that exposes sensitive values like VELA_SOURCE_CLIENT and VELA_SECRET (GitHub Advisory).

Impact

The vulnerability allows unauthorized access to sensitive server configuration data, including OAuth client IDs used for GitHub communication and secrets used for server-worker communication. This could potentially lead to further compromise of the Vela infrastructure (GitHub Advisory).

Exploitability

The vulnerability can be exploited by creating a malicious pipeline template that uses the Sprig env function to access server environment variables. No special privileges are required beyond the ability to create pipeline templates (GitHub Advisory).

Mitigation and workarounds

The vulnerability has been patched in version 0.6.1. Users should upgrade to this version or later. Additionally, it is recommended to rotate all secrets after upgrading. There are no known workarounds for this vulnerability (GitHub Advisory, Vela Patch).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management