GHSA-xvh9-35w9-42m4: Path Traversal
Impact
Catalog entity providers for Azure Blob Storage and AWS S3 did not sufficiently validate storage object paths, which could allow catalog descriptors to be read from outside the intended storage boundary. Access is limited to locations reachable by the backend's configured credentials.
Patches
- @backstage/plugin-catalog-backend-module-azure version 0.3.21 - @backstage/plugin-catalog-backend-module-aws version 0.4.27 - @backstage/backend-defaults version 0.7.18
Workarounds
- Restrict blob and object creation or renaming in configured catalog storage sources to trusted principals. - Scope Backstage's Azure and AWS reader credentials and network access to the intended storage boundaries. - Disable an affected catalog provider if those restrictions cannot be enforced.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/@backstage/backend-defaultsto a version that resolves this vulnerability.Fixed in 0.17.8 - Upgrade
Upgrade
npm/@backstage/plugin-catalog-backend-module-awsto a version that resolves this vulnerability.Fixed in 0.4.27 - Upgrade
Upgrade
npm/@backstage/plugin-catalog-backend-module-azureto a version that resolves this vulnerability.Fixed in 0.3.21 - Upgrade
Upgrade
@backstage/backend-defaultsto a version that resolves this vulnerability.Fixed in 0.7.18 - Upgrade
Upgrade
@backstage/plugin-catalog-backend-module-awsto a version that resolves this vulnerability.Fixed in 0.4.27 - Upgrade
Upgrade
@backstage/plugin-catalog-backend-module-azureto a version that resolves this vulnerability.Fixed in 0.3.21 - Configuration
Disable the affected catalog provider if restrictions on catalog storage access cannot be enforced.
Affected catalog provider - Compensating control
Restrict blob and object creation or renaming in configured catalog storage sources to trusted principals.
- Compensating control
Scope Backstage's Azure and AWS reader credentials and network access to the intended storage boundaries.
Event History
Frequently Asked Questions
Who is exposed to this issue?
Backstage deployments using the Azure Blob Storage or AWS S3 catalog entity providers are exposed if untrusted principals can create or rename objects in configured catalog storage sources. The possible read access is limited to locations reachable with the backend's configured credentials.
What does an attacker need to exploit it?
An attacker needs the ability to influence object paths in a configured catalog storage source, such as by creating or renaming blobs or objects. Exploitation also depends on the backend credentials and network access being able to reach the target location.
Which versions contain fixes?
Fixed versions are @backstage/plugin-catalog-backend-module-azure 0.3.21, @backstage/plugin-catalog-backend-module-aws 0.4.27, and @backstage/backend-defaults 0.7.18.
What can be done if patching cannot happen immediately?
Restrict creation and renaming of blobs or objects in configured catalog sources to trusted principals. Also scope Azure and AWS reader credentials and network access to the intended storage boundaries; disable an affected catalog provider if these restrictions cannot be enforced.