GHSA-qgvj-qcf8-xq73: SSRF
Impact
An authenticated Backstage user could craft a catalog entity with placeholder directives that reference resources outside the entity's source repository. Under certain configurations, this could allow access to data not intended to be available to the user.
Patches
Patched in @backstage/plugin-catalog-backend version 3.9.1
Workarounds
If you're not able to update immediately:
- Limit the scope of integration credentials (e.g., GitHub tokens) to only the repositories that Backstage needs to access.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/@backstage/plugin-catalog-backendto a version that resolves this vulnerability.Fixed in 3.9.1 - Upgrade
Upgrade
@backstage/plugin-catalog-backendto a version that resolves this vulnerability.Fixed in 3.9.1 - Compensating control
Limit the scope of integration credentials, such as GitHub tokens, to only the repositories that Backstage needs to access.
Event History
Frequently Asked Questions
Who is exposed to this issue?
Backstage deployments using @backstage/plugin-catalog-backend are exposed if authenticated users can create catalog entities and the relevant configuration permits placeholder directives to reference resources outside the entity's source repository.
What does an attacker need to exploit it?
An attacker needs to be an authenticated Backstage user and be able to craft a catalog entity containing placeholder directives. Exploitation depends on configuration that allows those directives to reference external resources.
How can the risk be reduced before upgrading?
Limit integration credential scope, such as GitHub tokens, to only the repositories that Backstage needs to access. This reduces the external resources available through those credentials.
Which version contains the fix?
The issue is patched in @backstage/plugin-catalog-backend version 3.9.1.