GHSA-7hfw-grcm-cqm6: Medium severity npm/@backstage/plugin-scaffolder-backend vulnerability
Impact
An authenticated internal user may be able to view metadata for scaffolder tasks outside the visibility intended by a deployment's permission policy. Stored task secrets are not included in the affected response, and no integrity or availability impact was identified.
Patches
Patched in @backstage/plugin-scaffolder-backend version 4.1.0
Workarounds
- Restrict the scaffolder task-list endpoint at the ingress or authenticating proxy to users who are permitted to view all tasks. - Avoid placing sensitive values in template input parameters until the patched package is deployed.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/@backstage/plugin-scaffolder-backendto a version that resolves this vulnerability.Fixed in 4.1.0 - Upgrade
Upgrade
@backstage/plugin-scaffolder-backendto a version that resolves this vulnerability.Fixed in 4.1.0 - Compensating control
Avoid placing sensitive values in template input parameters until the patched package is deployed.
- Compensating control
Restrict the scaffolder task-list endpoint at the ingress or authenticating proxy to users permitted to view all tasks.
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated internal user may be able to exploit it. The issue concerns users who can reach the scaffolder task-list endpoint but are not intended to view all scaffolder tasks under the deployment's permission policy.
What information could be exposed?
The affected response may expose metadata for scaffolder tasks outside the intended visibility policy. Stored task secrets are not included, and no integrity or availability impact was identified.
Are default deployments affected?
The provided information does not identify whether a default configuration is affected. Exposure depends on access to the scaffolder task-list endpoint and the deployment's task visibility permission policy.
What can be done before upgrading?
Restrict the scaffolder task-list endpoint at the ingress or authenticating proxy so that only users permitted to view all tasks can access it. Avoid putting sensitive values in template input parameters until the patched package is deployed.
What version contains the fix?
The issue is patched in @backstage/plugin-scaffolder-backend version 4.1.0.