GHSA-g8rx-f7m5-7794: Path Traversal
Impact
An authenticated user who can execute an eligible template and influence an allowed Bitbucket repository could affect filesystem paths outside the expected working area. Depending on the backend deployment, this could compromise backend confidentiality, integrity, or availability.
Patches
- @backstage/plugin-scaffolder-backend-module-bitbucket-cloud version 0.3.10 - @backstage/plugin-scaffolder-backend-module-bitbucket-server version 0.2.25
Workarounds
- Restrict execution of affected Scaffolder templates to trusted users. - Avoid templates that accept user-controlled target repositories for these actions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/@backstage/plugin-scaffolder-backend-module-bitbucket-serverto a version that resolves this vulnerability.Fixed in 0.2.25 - Upgrade
Upgrade
npm/@backstage/plugin-scaffolder-backend-module-bitbucket-cloudto a version that resolves this vulnerability.Fixed in 0.3.10 - Upgrade
Upgrade
@backstage/plugin-scaffolder-backend-module-bitbucket-cloudto a version that resolves this vulnerability.Fixed in 0.3.10 - Upgrade
Upgrade
@backstage/plugin-scaffolder-backend-module-bitbucket-serverto a version that resolves this vulnerability.Fixed in 0.2.25 - Compensating control
Avoid templates that accept user-controlled target repositories for these actions.
- Compensating control
Restrict execution of affected Scaffolder templates to trusted users.
Event History
Frequently Asked Questions
Who is exposed to this issue?
Deployments using the affected Bitbucket Cloud or Bitbucket Server Scaffolder backend modules are exposed when an authenticated user can execute an eligible template and influence an allowed Bitbucket repository. The impact depends on the backend deployment, and may affect confidentiality, integrity, or availability.
What access does an attacker need?
An attacker needs authenticated access, permission to execute an eligible Scaffolder template, and the ability to influence an allowed Bitbucket repository. User interaction is not required.
Which versions include fixes?
Fixed versions are @backstage/plugin-scaffolder-backend-module-bitbucket-cloud 0.3.10 and @backstage/plugin-scaffolder-backend-module-bitbucket-server 0.2.25.
What can be done if patching cannot happen immediately?
Restrict execution of affected Scaffolder templates to trusted users. Also avoid templates that accept user-controlled target repositories for the affected actions.