Expected Behavior Violation Affecting @backstage/plugin-app-backend package, versions <0.3.75


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.07% (23rd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JS-BACKSTAGEPLUGINAPPBACKEND-8163063
  • published6 Oct 2024
  • disclosed3 Oct 2024
  • creditUnknown

Introduced: 3 Oct 2024

CVE-2024-47762  (opens in a new tab)
CWE-440  (opens in a new tab)

How to fix?

Upgrade @backstage/plugin-app-backend to version 0.3.75 or higher.

Overview

@backstage/plugin-app-backend is an A Backstage backend plugin that serves the Backstage frontend app

Affected versions of this package are vulnerable to Expected Behavior Violation due to the handling of APP_CONFIG_* environment variables, which ignores the visibility defined in the configuration schema. Note: This was an intended feature of the APP_CONFIG_* way of supplying configuration, but it goes against the expected behavior of the configuration system.

Workaround

This vulnerability can be mitigated by avoiding using the APP_CONFIG_ configuration pattern for secrets.

CVSS Base Scores

version 4.0
version 3.1