GHSA-qmw3-745m-w99g: High severity npm/@backstage/plugin-techdocs-node vulnerability
Impact
An attacker who can provide configuration to a TechDocs build may execute code in the generator runtime. Impact is greatest when documentation generation runs with backend credentials or host access.
Patches
Patched in @backstage/plugin-techdocs-node version 1.15.4.
Workarounds
Use external TechDocs generation in an isolated environment without sensitive credentials or host access. Restrict and review changes to documentation configuration before generation.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/@backstage/plugin-techdocs-nodeto a version that resolves this vulnerability.Fixed in 1.15.4 - Upgrade
Upgrade
@backstage/plugin-techdocs-nodeto a version that resolves this vulnerability.Fixed in 1.15.4 - Compensating control
Restrict and review changes to documentation configuration before generation.
- Compensating control
Run external TechDocs generation in an isolated environment without sensitive credentials or host access.
Event History
Frequently Asked Questions
Who is realistically exposed to exploitation?
Deployments are exposed when an attacker can provide configuration to a TechDocs build. The impact is greatest where documentation generation has backend credentials or access to the host.
What level of access does an attacker need?
The attacker needs the ability to provide configuration to a TechDocs build. No user interaction is required.
What can be done if patching cannot happen immediately?
Use external TechDocs generation in an isolated environment without sensitive credentials or host access. Restrict and review changes to documentation configuration before generation.
Which version contains the fix?
The issue is patched in @backstage/plugin-techdocs-node version 1.15.4.