296,733
Total vulnerabilities in the database
Vela is a Pipeline Automation (CI/CD) framework built on Linux container technology written in Golang. An authentication mechanism added in version 0.7.0 enables some malicious user to obtain secrets utilizing the injected credentials within the ~/.netrc file. Refer to the referenced GitHub Security Advisory for complete details. This is fixed in version 0.7.5.
| Software | From | Fixed in |
|---|---|---|
| go-vela / vela | - | 0.7.5 |
github.com/go-vela/server
|
0.7.0 | 0.7.5 |
github.com/go-vela/server/api
|
0.7.0 | 0.7.5 |