GHSA-mfvq-x7vr-rgqg: Medium severity npm/@backstage/plugin-scaffolder-backend vulnerability
Impact
Deployments that configure sensitive scaffolder.defaultEnvironment.secrets and allow an attacker to create or modify Scaffolder templates are affected. A template author could cause secret-derived values used during template iteration to be persisted in task logs, exposing those values to users with access to the resulting task logs.
Patches
Patched in @backstage/plugin-scaffolder-backend version 4.1.0
Workarounds
- Restrict permission to create or update Template entities to fully trusted parties, as recommended by the Backstage threat model. - If that restriction cannot be guaranteed, remove sensitive values from scaffolder.defaultEnvironment.secrets until a patched version is available.
No complete workaround is known that preserves both untrusted template authoring and access to sensitive default-environment secrets.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/@backstage/plugin-scaffolder-backendto a version that resolves this vulnerability.Fixed in 4.1.0 - Upgrade
Upgrade
@backstage/plugin-scaffolder-backendto a version that resolves this vulnerability.Fixed in 4.1.0 - Configuration
Remove sensitive values from scaffolder.defaultEnvironment.secrets until the patched version is available.
Backstage Scaffolder scaffolder.defaultEnvironment.secrets = remove sensitive values - Compensating control
Restrict permission to create or update Template entities to fully trusted parties.
Event History
Frequently Asked Questions
Which deployments are affected?
Affected deployments both configure sensitive values in scaffolder.defaultEnvironment.secrets and permit an attacker to create or modify Scaffolder templates. Deployments that do not meet both conditions are not identified as affected by the advisory.
What access does an attacker need?
An attacker needs permission to create or update a Scaffolder Template entity. They can then author a template that causes secret-derived values used during template iteration to be written to task logs.
Who could view exposed secret values?
The secret-derived values may be exposed to users who have access to the resulting task logs. The advisory does not state that the attacker needs direct access to those logs to cause the disclosure.
What should be done if upgrading is not immediately possible?
Restrict Template entity creation and update permissions to fully trusted parties. If that cannot be ensured, remove sensitive values from scaffolder.defaultEnvironment.secrets; no complete workaround preserves both untrusted template authoring and sensitive default-environment secrets.
What version contains the fix?
The issue is patched in @backstage/plugin-scaffolder-backend version 4.1.0.