GHSA-29gx-h2m3-xw44: Medium severity npm/@backstage/plugin-scaffolder-backend-module-bitbucket-server vulnerability
Impact
Scaffolder actions that interact with source control systems may not consistently enforce the intended credential boundaries under certain configurations. An authenticated user could perform operations with broader access than intended.
Patches
- @backstage/plugin-scaffolder-backend version 4.1.0 - @backstage/plugin-scaffolder-backend-module-azure version 0.2.25 - @backstage/plugin-scaffolder-backend-module-bitbucket-cloud version 0.3.10 - @backstage/plugin-scaffolder-backend-module-bitbucket-server version 0.2.25 - @backstage/plugin-scaffolder-backend-module-github version 0.9.13 - @backstage/plugin-scaffolder-backend-module-gitlab version 0.11.10
The fix introduces a new configuration option that enforces user-provided credentials for supported SCM actions. The new behavior is opt-in for compatibility. After upgrading, set:
yaml scaffolder: requireScmUserCredentials: true
Before enabling this setting, review and update your templates as described in the software templates documentation referred to below.
Workarounds
If you cannot upgrade and enable the setting immediately:
- Restrict who can create Scaffolder tasks and which templates they can execute. - Limit SCM integration credentials to the minimum repository read and mutation permissions required. - Remove integration credentials for SCM hosts where all required operations can use explicitly supplied user tokens.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/@backstage/plugin-scaffolder-backend-module-bitbucket-serverto a version that resolves this vulnerability.Fixed in 0.2.25 - Upgrade
Upgrade
npm/@backstage/plugin-scaffolder-backend-module-bitbucket-cloudto a version that resolves this vulnerability.Fixed in 0.3.10 - Upgrade
Upgrade
npm/@backstage/plugin-scaffolder-backend-module-azureto a version that resolves this vulnerability.Fixed in 0.2.25 - Upgrade
Upgrade
npm/@backstage/plugin-scaffolder-backend-module-gitlabto a version that resolves this vulnerability.Fixed in 0.11.10 - Upgrade
Upgrade
npm/@backstage/plugin-scaffolder-backend-module-githubto a version that resolves this vulnerability.Fixed in 0.9.13 - Upgrade
Upgrade
npm/@backstage/plugin-scaffolder-backendto a version that resolves this vulnerability.Fixed in 4.1.0 - Upgrade
Upgrade
@backstage/plugin-scaffolder-backend-module-azureto a version that resolves this vulnerability.Fixed in 0.2.25 - Upgrade
Upgrade
@backstage/plugin-scaffolder-backend-module-bitbucket-cloudto a version that resolves this vulnerability.Fixed in 0.3.10 - Upgrade
Upgrade
@backstage/plugin-scaffolder-backend-module-bitbucket-serverto a version that resolves this vulnerability.Fixed in 0.2.25 - Upgrade
Upgrade
@backstage/plugin-scaffolder-backend-module-githubto a version that resolves this vulnerability.Fixed in 0.9.13 - Upgrade
Upgrade
@backstage/plugin-scaffolder-backend-module-gitlabto a version that resolves this vulnerability.Fixed in 0.11.10 - Upgrade
Upgrade
@backstage/plugin-scaffolder-backendto a version that resolves this vulnerability.Fixed in 4.1.0 - Configuration
Set requireScmUserCredentials to true to enforce user-provided credentials for supported SCM actions; review and update templates before enabling it.
Backstage Scaffolder requireScmUserCredentials = true - Compensating control
Limit SCM integration credentials to the minimum repository read and mutation permissions required.
- Compensating control
Remove integration credentials for SCM hosts where all required operations can use explicitly supplied user tokens.
- Compensating control
Restrict who can create Scaffolder tasks and which templates they can execute.