@backstage/backend-defaults@0.0.0-nightly-20240522021554

Backend defaults used by Backstage backend apps

  • latest version

    0.18.0

  • latest non vulnerable version

  • first published

    4 years ago

  • latest version published

    26 days ago

  • Direct Vulnerabilities

    Known vulnerabilities in the @backstage/backend-defaults package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    External Control of File Name or Path

    @backstage/backend-defaults is a Backend defaults used by Backstage backend apps

    Affected versions of this package are vulnerable to External Control of File Name or Path via the cloud storage URL reader implementations (AwsS3UrlReader, AwsCodeCommitUrlReader, AzureBlobStorageUrlReader, and GoogleGcsUrlReader) when processing object or blob names that contain dot path segments (. or ..). An attacker who can influence the names of objects stored in a cloud storage bucket or repository can cause the reader to traverse outside the intended directory, potentially writing or overwriting files at unintended paths on the server.

    How to fix External Control of File Name or Path?

    Upgrade @backstage/backend-defaults to version 0.17.8 or higher.

    <0.17.8
    • L
    Directory Traversal

    @backstage/backend-defaults is a Backend defaults used by Backstage backend apps

    Affected versions of this package are vulnerable to Directory Traversal via the parseUrl functions in AwsS3UrlReader.ts and AzureBlobStorageUrlReader.ts, where URL path segments are not validated for dot-segment sequences before being used to construct storage paths. An attacker with sufficient privileges can supply a URL containing percent-encoded dot segments (e.g. %2e%2e) to traverse outside the intended bucket or container path and read arbitrary objects from AWS S3 or Azure Blob Storage.

    How to fix Directory Traversal?

    Upgrade @backstage/backend-defaults to version 0.17.8 or higher.

    <0.17.8
    • H
    Incorrect Authorization

    @backstage/backend-defaults is a Backend defaults used by Backstage backend apps

    Affected versions of this package are vulnerable to Incorrect Authorization via the service credential delegation path in DefaultAuthService, when a token issued to an external service principal carries access restrictions (such as read-only). During plugin-to-plugin token delegation, the getPluginRequestToken flow previously did not propagate or enforce the per-plugin access restriction map (allAccessRestrictions), allowing the restricted credential to obtain a delegated plugin token with full access to any target plugin, bypassing the configured restrictions.

    Note: This is only exploitable when an external service credential is configured with access restrictions.

    How to fix Incorrect Authorization?

    Upgrade @backstage/backend-defaults to version 0.16.1, 0.17.8 or higher.

    <0.16.1>=0.17.0 <0.17.8
    • L
    Server-side Request Forgery (SSRF)

    @backstage/backend-defaults is a Backend defaults used by Backstage backend apps

    Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) via the FetchUrlReader component that automatically follows HTTP redirects. An attacker can access internal or sensitive resources by controlling a host listed in backend.reading.allow and issuing HTTP redirects to URLs that are not on the allowlist, thereby bypassing security controls.

    How to fix Server-side Request Forgery (SSRF)?

    Upgrade @backstage/backend-defaults to version 0.12.2, 0.13.2, 0.14.1 or higher.

    <0.12.2>=0.13.0-next.0 <0.13.2>=0.14.0-next.0 <0.14.1
    • H
    Symlink Attack

    @backstage/backend-defaults is a Backend defaults used by Backstage backend apps

    Affected versions of this package are vulnerable to Symlink Attack via multiple actions, including debug:log, fs:delete, and archive extraction. A user who create and execute Scaffolder templates can read, delete, or write arbitrary files outside the intended workspace.

    How to fix Symlink Attack?

    Upgrade @backstage/backend-defaults to version 0.12.2, 0.13.2, 0.14.1 or higher.

    <0.12.2>=0.13.0-next.0 <0.13.2>=0.14.0-next.0 <0.14.1