GHSA-hmp2-4m7g-22cv: High severity npm/@backstage/plugin-scaffolder-backend vulnerability
Impact
An authenticated user with access to affected Scaffolder templates could bypass configured action restrictions. Depending on integration credentials, this could grant unauthorized access to repositories and related source-control resources.
Patches
Patched in @backstage/plugin-scaffolder-backend version 4.1.0
Workarounds
- Restrict affected Scaffolder actions to trusted users and configure source-control integrations with least-privilege credentials.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/@backstage/plugin-scaffolder-backendto a version that resolves this vulnerability.Fixed in 4.1.0 - Upgrade
Upgrade
npm/@backstage/plugin-scaffolder-backendto a version that resolves this vulnerability.Fixed in 4.0.3 - Upgrade
Upgrade
npm/@backstage/plugin-scaffolder-backendto a version that resolves this vulnerability.Fixed in 3.4.1 - Upgrade
Upgrade
npm/@backstage/plugin-scaffolder-backendto a version that resolves this vulnerability.Fixed in 3.3.1 - Upgrade
Upgrade
@backstage/plugin-scaffolder-backendto a version that resolves this vulnerability.Fixed in 4.1.0 - Compensating control
Restrict affected Scaffolder actions to trusted users and configure source-control integrations with least-privilege credentials.
Event History
Frequently Asked Questions
Who is realistically exposed to this issue?
Organizations using affected Scaffolder templates where authenticated users can access template actions are exposed. The impact depends on the permissions of configured source-control integration credentials.
What does an attacker need to exploit it?
An attacker needs to be an authenticated user with access to affected Scaffolder templates. No user interaction is required.
What should be done if upgrading is not immediately possible?
Restrict access to affected Scaffolder actions to trusted users. Configure source-control integrations with least-privilege credentials to limit repository and related source-control access if restrictions are bypassed.
What version contains the fix?
The issue is patched in @backstage/plugin-scaffolder-backend version 4.1.0.