Количество 2
Количество 2
CVE-2021-21432
Vela is a Pipeline Automation (CI/CD) framework built on Linux container technology written in Golang. An authentication mechanism added in version 0.7.0 enables some malicious user to obtain secrets utilizing the injected credentials within the `~/.netrc` file. Refer to the referenced GitHub Security Advisory for complete details. This is fixed in version 0.7.5.
GHSA-8j3f-mhq8-gmh4
Reject unauthorized access with GitHub PATs
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2021-21432 Vela is a Pipeline Automation (CI/CD) framework built on Linux container technology written in Golang. An authentication mechanism added in version 0.7.0 enables some malicious user to obtain secrets utilizing the injected credentials within the `~/.netrc` file. Refer to the referenced GitHub Security Advisory for complete details. This is fixed in version 0.7.5. | CVSS3: 7.5 | 0% Низкий | почти 5 лет назад | |
GHSA-8j3f-mhq8-gmh4 Reject unauthorized access with GitHub PATs | CVSS3: 7.5 | 0% Низкий | почти 4 года назад |
Уязвимостей на страницу