GHSA-7649-wm97-w3j3: Path Traversal
Impact
An attacker with write access to a cloud storage bucket used by Backstage could craft object names that could collide with protected files in the output directory. In certain deployment configurations, this could lead to content injection.
Patches
Patched in @backstage/backend-defaults version 0.17.8
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/@backstage/backend-defaultsto a version that resolves this vulnerability.Fixed in 0.17.8 - Upgrade
Upgrade
@backstage/backend-defaultsto a version that resolves this vulnerability.Fixed in 0.17.8