Vulnerability GHSA-3x3f-jcp3-g22j
Medium Risk
MEDIUM RISK
CVSS Score: 6.5
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
2 years ago
September 17, 2024 at 09:29 PM UTC
@backstage/plugin-catalog-backend Prototype Pollution vulnerability
0.0.0-nightly-20201012104 - 1.26.0-next.2
0.0.0-nightly-20201012104 - 1.26.0-next.2
Summary
@backstage/plugin-catalog-backend Prototype Pollution vulnerability
Details
Impact
A malicious actor with authenticated access to a Backstage instance with the catalog backend plugin installed is able to interrupt the service using a specially crafted query to the catalog API.
Patches
This has been fixed in the 1.26.0 release of the @backstage/plugin-catalog-backend package.
References
If you have any questions or comments about this advisory:
Open an issue in the Backstage repository Visit our Discord, linked to in Backstage README
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Low Risk
3 hours ago
Backstage: Inconsistent enforcement of allowed location types during catalog processing
0.0.0-nightly-20201012104 - 3.9.0 GHSA-pcmq-25r3-5w9v
0.0.0-nightly-20201012104 - 3.9.0 GHSA-pcmq-25r3-5w9v
Medium Risk
3 years ago
Cross site scripting Vulnerability in backstage Software Catalog
0.0.0-nightly-20201012104 - 1.7.2-next.2 GHSA-7hv8-3fr9-j2hv
0.0.0-nightly-20201012104 - 1.7.2-next.2 GHSA-7hv8-3fr9-j2hv
Impacted packages
Timeline
Published
2 years ago
September 17, 2024 at 09:29 PM UTC
Fixed (1.26.0)
Unknown
Unknown
Last Modified
1 year ago
November 18, 2024 at 04:27 PM UTC