GHSA-75qf-886x-5xf2: Path Traversal
Impact
Insufficient input validation in the Confluence to Markdown scaffolder module could allow an attacker to influence file write operations during template execution. Exploitation requires a Backstage user to run a template that processes attacker-influenced Confluence content.
Patches
Patched in @backstage/plugin-scaffolder-backend-module-confluence-to-markdown version 0.3.25
Workarounds
If unable to update immediately:
- Restrict Confluence edit access to trusted users. - Review Confluence page content before running scaffolder templates against untrusted pages.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/@backstage/plugin-scaffolder-backend-module-confluence-to-markdownto a version that resolves this vulnerability.Fixed in 0.3.25 - Upgrade
Upgrade
@backstage/plugin-scaffolder-backend-module-confluence-to-markdownto a version that resolves this vulnerability.Fixed in 0.3.25 - Compensating control
Restrict Confluence edit access to trusted users.
- Compensating control
Review Confluence page content before running scaffolder templates against untrusted pages.
Event History
Frequently Asked Questions
Who is exposed to this issue?
Backstage deployments using the Confluence to Markdown scaffolder module are exposed when users can run templates that process Confluence content influenced by an attacker. The attacker must be able to influence that Confluence content, such as through page editing access.
What access and interaction are required for exploitation?
Exploitation requires a Backstage user to run a scaffolder template against attacker-influenced Confluence content. The CVSS vector indicates network reachability, low attack complexity, low privileges, and user interaction.
Which version contains the fix?
The issue is patched in @backstage/plugin-scaffolder-backend-module-confluence-to-markdown version 0.3.25.
What can be done if updating is not immediately possible?
Restrict Confluence edit access to trusted users. Review Confluence page content before running scaffolder templates against pages that may be untrusted.