CVE-2022-39395 is a critical vulnerability affecting Vela Server, Worker, and UI versions prior to 0.16.0 and 0.17.0 respectively, stemming from insecure default configurations that allow exploitation and container breakouts within the CI/CD framework. With a CVSS score of 9.9, this vulnerability presents a critical risk (AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H), meaning it can be exploited remotely with low complexity by a low-privileged attacker, leading to complete compromise of confidentiality, integrity, and availability. While the vulnerability is not currently on the KEV catalog or Hot List, and there is no known public exploit code or significant community discussion, immediate patching to the recommended versions (Server 0.16.0, Worker 0.16.0, UI 0.17.0) and subsequent configuration adjustments are crucial to mitigate the high risk exposure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.16.0CPE matchmatch criteria | cpe:2.3:a:go-vela:server:*:*:*:*:*:*:*:* | ||
< 0.17.0CPE matchmatch criteria | cpe:2.3:a:go-vela:ui:*:*:*:*:*:*:*:* | ||
< 0.16.0CPE matchmatch criteria | cpe:2.3:a:go-vela:worker:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 1.0 Bluesky, 0.5 Mastodon, and 1.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.