Register for the AI for Security Summit: Join Figma, Perplexity & Wiz
Vulnerability DatabaseGHSA-v8mx-hp2q-gw85

GHSA-v8mx-hp2q-gw85
vulnerability analysis and mitigation

Overview

A high severity vulnerability (GHSA-v8mx-hp2q-gw85) was discovered in the Golang SDK for Vela affecting versions <= 0.23.1. The vulnerability, published on March 12, 2024, allows for insecure variable substitution in Vela pipelines where sensitive information can be exposed through various pipeline configurations. The issue has been assigned a CVSS score of 7.7 and primarily affects the go-vela/sdk-go package (GitHub Advisory).

Technical details

The vulnerability enables variable substitution combined with insensitive fields like parameters, image, and entrypoint to inject secrets into a plugin/image, potentially bypassing log masking and exposing secrets without using the commands block. This particularly impacts secrets restricted by the 'no commands' option. The vulnerability has been assigned CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N, indicating network attack vector, low attack complexity, low privileges required, and no user interaction needed (GitHub Advisory).

Impact

The vulnerability can lead to unintended exposure of secret values and increased risk during image execution by bypassing log masking. While Vela provides secrets masking, the vulnerability allows secrets to be exposed if they are not handled properly or are altered. This creates a false sense of security for users who rely on image and command restrictions to protect their secrets (GitHub Advisory).

Exploitability

Exploitation requires a pipeline author to supply secrets to a plugin designed to print parameters in logs. The vulnerability can be exploited through various methods including using parameters with variable substitution, using image tags with secret injection, or using entrypoint as a command shim. This behavior is particularly concerning for secrets restricted by the 'no commands' option (GitHub Advisory).

Mitigation and workarounds

Several workarounds have been recommended: avoid providing sensitive values to plugins that could potentially expose them, ensure plugins follow best practices for handling sensitive parameters, minimize secrets with pull_request events enabled, implement build approval settings to restrict builds from untrusted users, and limit the use of shared secrets. A patch has been released in version 0.23.2 (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management