—
GO-2022-1100
Vela Insecure Defaults in github.com/go-vela/server
Quick fix
GO-2022-1100 — github.com/go-vela/server: upgrade to the fixed version with the command below.
go get github.com/go-vela/server@v0.16.0Details
Vela Insecure Defaults in github.com/go-vela/server
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/go-vela/server
Introduced in:
0Fixed in: 0.16.0Fix
go get github.com/go-vela/server@v0.16.0Go/github.com/go-vela/worker
Introduced in:
0Fixed in: 0.16.0Fix
go get github.com/go-vela/worker@v0.16.0References
- https://github.com/go-vela/server/security/advisories/GHSA-5m7g-pj8w-7593[ADVISORY]
- https://github.com/go-vela/ui/security/advisories/GHSA-xf39-98m2-889v[ADVISORY]
- https://github.com/go-vela/worker/security/advisories/GHSA-2w78-ffv6-p46w[ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2022-39395[ADVISORY]
- https://github.com/go-vela/server/commit/05558ee99d70f7d6f83bed7c8f78ac0b35fa26f4[FIX]
- https://docs.docker.com/engine/security/#docker-daemon-attack-surface[WEB]
- https://github.com/go-vela/server/releases/tag/v0.16.0[WEB]
- https://github.com/go-vela/ui/releases/tag/v0.17.0[WEB]
- https://github.com/go-vela/worker/releases/tag/v0.16.0[WEB]
- https://go-vela.github.io/docs/installation/server/reference/#vela_repo_allowlist[WEB]
- https://go-vela.github.io/docs/installation/worker/reference/#vela_runtime_privileged_images[WEB]