CVE-2024-45815: Prototype pollution in @backstage/plugin-catalog-backend
Impact
A malicious actor with authenticated access to a Backstage instance with the catalog backend plugin installed is able to interrupt the service using a specially crafted query to the catalog API.
Patches
This has been fixed in the 1.26.0 release of the @backstage/plugin-catalog-backend package.
References
If you have any questions or comments about this advisory:
Open an issue in the Backstage repository Visit our Discord, linked to in Backstage README
Other sources
Backstage is an open framework for building developer portals. A malicious actor with authenticated access to a Backstage instance with the catalog backend plugin installed is able to interrupt the service using a specially crafted query to the catalog API. This has been fixed in the 1.26.0 release of the @backstage/plugin-catalog-backend. All users are advised to upgrade. There are no known workarounds for this vulnerability.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-45815?
CVE-2024-45815 has a high severity, as it allows authenticated users to interrupt the service.
How do I fix CVE-2024-45815?
To fix CVE-2024-45815, upgrade to version 1.26.0 or later of the Backstage catalog backend plugin.
What types of software are affected by CVE-2024-45815?
CVE-2024-45815 affects Backstage installations with the catalog backend plugin before version 1.26.0.
Who can exploit CVE-2024-45815?
Any malicious actor with authenticated access to a Backstage instance can exploit CVE-2024-45815.
What is the impact of CVE-2024-45815?
The impact of CVE-2024-45815 is that it can disrupt service by executing a specially crafted query to the catalog API.