High severity7.4NVD Advisory· Published Jan 4, 2021· Updated Jun 17, 2026
CVE-2020-26294
CVE-2020-26294
Description
Vela is a Pipeline Automation (CI/CD) framework built on Linux container technology written in Golang. In Vela compiler before version 0.6.1 there is a vulnerability which allows exposure of server configuration. It impacts all users of Vela. An attacker can use Sprig's env function to retrieve configuration information, see referenced GHSA for an example. This has been fixed in version 0.6.1. In addition to upgrading, it is recommended to rotate all secrets.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/go-vela/compilerGo | < 0.6.1 | 0.6.1 |
Affected products
3- go-vela/compilerv5Range: < 0.6.1
Patches
Vulnerability mechanics
References
6- github.com/go-vela/compiler/commit/f1ace5f8a05c95c4d02264556e38a959ee2d9bdanvdPatchThird Party AdvisoryWEB
- github.com/go-vela/compiler/security/advisories/GHSA-gv2h-gf8m-r68jnvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-gv2h-gf8m-r68jghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-26294ghsaADVISORY
- pkg.go.dev/github.com/go-vela/compiler/compilernvdProductThird Party AdvisoryWEB
- github.com/helm/helm/blob/6297c021cbda1483d8c08a8ec6f4a99e38be7302/pkg/engine/funcs.goghsaWEB
News mentions
0No linked articles in our index yet.