Go Vela is a continuous-integration and deployment platform whose vulnerability footprint centers on its core server, worker, and UI components. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Go Vela over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-39395CRITICAL Vela is a Pipeline Automation (CI/CD) framework built on Linux container technology written in Golang. In Vela Server and Vela Worker prior to version 0.16.0 and Vela UI prior to v | Nov 10, 2022 | 9.9 | 30 | NO | NO |
CVE-2021-21432MEDIUM Vela is a Pipeline Automation (CI/CD) framework built on Linux container technology written in Golang. An authentication mechanism added in version 0.7.0 enables some malicious use | Apr 9, 2021 | 6.5 | 22 | NO | NO |
CVE-2024-28236MEDIUM Vela is a Pipeline Automation (CI/CD) framework built on Linux container technology written in Golang. Vela pipelines can use variable substitution combined with insensitive fields | Mar 12, 2024 | 6.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Go Vela.
Media articles that mention a CVE ID that affects a product developed by Go Vela — matched by CVE ID, not by vendor name.