In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade github.com/go-vela/server/internal
to version 0.25.3, 0.26.3 or higher.
Affected versions of this package are vulnerable to User Impersonation via spoofing a webhook payload. A user with access to the vulnerable CI instance and the linked source control manager can take ownership of the contents of a repository. In subsequent builds they can then expose secrets contained in that repository.