Path Traversal Affecting @backstage/backend-common package, versions <0.19.10 >=0.20.0-next.0 <0.20.2 >=0.21.0-next.0 <0.21.1
Threat Intelligence
EPSS
0.05% (17th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-JS-BACKSTAGEBACKENDCOMMON-6274391
- published 25 Feb 2024
- disclosed 23 Feb 2024
- credit Unknown
Introduced: 23 Feb 2024
CVE-2024-26150 Open this link in a new tabHow to fix?
Upgrade @backstage/backend-common
to version 0.19.10, 0.20.2, 0.21.1 or higher.
Overview
@backstage/backend-common is a Common functionality library for Backstage backends
Affected versions of this package are vulnerable to Path Traversal due to insufficient symlink checks in the resolveSafeChildPath()
function.
CVSS Scores
version 3.1