GHSA-pcmq-25r3-5w9v: Path Traversal
Impact
Under certain configurations, the catalog backend could process location types that were not intended to be allowed, potentially leading to unintended file access on the backend host.
Patches
Patched in @backstage/plugin-catalog-backend version 3.9.1
Workarounds
No practical workarounds are available. Upgrade to the patched version.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/@backstage/plugin-catalog-backendto a version that resolves this vulnerability.Fixed in 3.9.1 - Upgrade
Upgrade
@backstage/plugin-catalog-backendto a version that resolves this vulnerability.Fixed in 3.9.1
Event History
Frequently Asked Questions
Which deployments should prioritize remediation?
Deployments using @backstage/plugin-catalog-backend under configurations that can cause unintended location types to be processed should prioritize upgrading. The advisory does not identify the specific configurations or location types involved.
What level of attacker access is indicated by the published severity vector?
The published vector indicates network reachability, low privileges, no user interaction, and high attack complexity. The stated impact is limited to integrity, with no confidentiality or availability impact listed.
Is there a mitigation if an immediate upgrade is not possible?
No practical workaround is available. Upgrade @backstage/plugin-catalog-backend to version 3.9.1, which contains the patch.