GHSA-2cmg-v53w-8xfp: Path Traversal
Impact
An authenticated user who can execute an affected template and control its repository file location may cause generated content to be written outside the task workspace, within locations writable by the Backstage backend process.
Patches
Patched in @backstage/plugin-scaffolder-backend-module-confluence-to-markdown version 0.3.25
Workarounds
- Restrict execution of templates using the affected action to trusted users. - Remove or disable the affected action until the patched package is deployed.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/@backstage/plugin-scaffolder-backend-module-confluence-to-markdownto a version that resolves this vulnerability.Fixed in 0.3.25 - Upgrade
Upgrade
@backstage/plugin-scaffolder-backend-module-confluence-to-markdownto a version that resolves this vulnerability.Fixed in 0.3.25 - Configuration
Remove or disable the affected action until the patched package is deployed.
Backstage Scaffolder affected action = disabled - Compensating control
Restrict execution of templates using the affected action to trusted users.
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated user must be able to execute a template that uses the affected action and control the repository file location supplied to that action. The issue is therefore most relevant where untrusted or insufficiently trusted users can run such templates.
What could an attacker do?
An attacker could cause generated content to be written outside the task workspace, to locations writable by the Backstage backend process. The stated impact is integrity compromise and limited availability impact; no confidentiality impact is identified.
Which package version contains the fix?
The issue is patched in @backstage/plugin-scaffolder-backend-module-confluence-to-markdown version 0.3.25.
What can be done before the patch is deployed?
Restrict execution of templates using the affected action to trusted users. Alternatively, remove or disable the affected action until the patched package is deployed.