GHSA-9ghw-48h5-v2w5: Input Validation
Impact
An authenticated Backstage user could craft a request URL that causes the proxy-backend to forward the request to a path outside the configured base path on the target server. This is limited to target servers already configured as proxy endpoints and requires Backstage authentication by default.
Patches
Patched in @backstage/plugin-proxy-backend version 0.6.17
Workarounds
- Deploy a reverse proxy or WAF in front of Backstage that normalizes request paths before they reach the backend.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/@backstage/plugin-proxy-backendto a version that resolves this vulnerability.Fixed in 0.6.17 - Upgrade
Upgrade
@backstage/plugin-proxy-backendto a version that resolves this vulnerability.Fixed in 0.6.17 - Compensating control
Deploy a reverse proxy or WAF in front of Backstage that normalizes request paths before they reach the backend.