@backstage/plugin-app-backend@0.3.72-next.2 vulnerabilities

A Backstage backend plugin that serves the Backstage frontend app

  • latest version

    0.5.1

  • latest non vulnerable version

  • first published

    4 years ago

  • latest version published

    26 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the @backstage/plugin-app-backend package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Expected Behavior Violation

    @backstage/plugin-app-backend is an A Backstage backend plugin that serves the Backstage frontend app

    Affected versions of this package are vulnerable to Expected Behavior Violation due to the handling of APP_CONFIG_* environment variables, which ignores the visibility defined in the configuration schema. Note: This was an intended feature of the APP_CONFIG_* way of supplying configuration, but it goes against the expected behavior of the configuration system.

    How to fix Expected Behavior Violation?

    Upgrade @backstage/plugin-app-backend to version 0.3.75 or higher.

    <0.3.75