Expected Behavior Violation Affecting @backstage/plugin-app-backend package, versions <0.3.75
Threat Intelligence
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-JS-BACKSTAGEPLUGINAPPBACKEND-8163063
- published 6 Oct 2024
- disclosed 3 Oct 2024
- credit Unknown
Introduced: 3 Oct 2024
CVE-2024-47762 Open this link in a new tabHow to fix?
Upgrade @backstage/plugin-app-backend
to version 0.3.75 or higher.
Overview
@backstage/plugin-app-backend is an A Backstage backend plugin that serves the Backstage frontend app
Affected versions of this package are vulnerable to Expected Behavior Violation due to the handling of APP_CONFIG_*
environment variables, which ignores the visibility defined in the configuration schema.
Note: This was an intended feature of the APP_CONFIG_*
way of supplying configuration, but it goes against the expected behavior of the configuration system.
Workaround
This vulnerability can be mitigated by avoiding using the APP_CONFIG_
configuration pattern for secrets.