
Cloud Vulnerability DB
A community-led vulnerabilities database
A high severity vulnerability (GHSA-v8mx-hp2q-gw85) was discovered in the Golang SDK for Vela affecting versions <= 0.23.1. The vulnerability, published on March 12, 2024, allows for insecure variable substitution in Vela pipelines where sensitive information can be exposed through various pipeline configurations. The issue has been assigned a CVSS score of 7.7 and primarily affects the go-vela/sdk-go package (GitHub Advisory).
The vulnerability enables variable substitution combined with insensitive fields like parameters, image, and entrypoint to inject secrets into a plugin/image, potentially bypassing log masking and exposing secrets without using the commands block. This particularly impacts secrets restricted by the 'no commands' option. The vulnerability has been assigned CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N, indicating network attack vector, low attack complexity, low privileges required, and no user interaction needed (GitHub Advisory).
The vulnerability can lead to unintended exposure of secret values and increased risk during image execution by bypassing log masking. While Vela provides secrets masking, the vulnerability allows secrets to be exposed if they are not handled properly or are altered. This creates a false sense of security for users who rely on image and command restrictions to protect their secrets (GitHub Advisory).
Exploitation requires a pipeline author to supply secrets to a plugin designed to print parameters in logs. The vulnerability can be exploited through various methods including using parameters with variable substitution, using image tags with secret injection, or using entrypoint as a command shim. This behavior is particularly concerning for secrets restricted by the 'no commands' option (GitHub Advisory).
Several workarounds have been recommended: avoid providing sensitive values to plugins that could potentially expose them, ensure plugins follow best practices for handling sensitive parameters, minimize secrets with pull_request events enabled, implement build approval settings to restrict builds from untrusted users, and limit the use of shared secrets. A patch has been released in version 0.23.2 (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."