REDHAT-BUG-2431878: Path Traversal
Backstage is an open framework for building developer portals. Multiple Scaffolder actions and archive extraction utilities were vulnerable to symlink-based path traversal attacks. An attacker with access to create and execute Scaffolder templates could exploit symlinks to read arbitrary files via the debug:log action by creating a symlink pointing to sensitive files (e.g., /etc/passwd, configuration files, secrets); delete arbitrary files via the fs:delete action by creating symlinks pointing outside the workspace, and write files outside the workspace via archive extraction (tar/zip) containing malicious symlinks. This affects any Backstage deployment where users can create or execute Scaffolder templates. This vulnerability is fixed in @backstage/backend-defaults versions 0.12.2, 0.13.2, 0.14.1, and 0.15.0; @backstage/plugin-scaffolder-backend versions 2.2.2, 3.0.2, and 3.1.1; and @backstage/plugin-scaffolder-node versions 0.11.2 and 0.12.3. Users should upgrade to these versions or later. Some workarounds are available. Follow the recommendation in the Backstage Threat Model to limit access to creating and updating templates, restrict who can create and execute Scaffolder templates using the permissions framework, audit existing templates for symlink usage, and/or run Backstage in a containerized environment with limited filesystem access.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
@backstage/backend-defaultsto a version that resolves this vulnerability.Fixed in 0.12.2 - Upgrade
Upgrade
@backstage/backend-defaultsto a version that resolves this vulnerability.Fixed in 0.13.2 - Upgrade
Upgrade
@backstage/backend-defaultsto a version that resolves this vulnerability.Fixed in 0.14.1 - Upgrade
Upgrade
@backstage/backend-defaultsto a version that resolves this vulnerability.Fixed in 0.15.0 - Upgrade
Upgrade
@backstage/plugin-scaffolder-backendto a version that resolves this vulnerability.Fixed in 2.2.2 - Upgrade
Upgrade
@backstage/plugin-scaffolder-backendto a version that resolves this vulnerability.Fixed in 3.0.2 - Upgrade
Upgrade
@backstage/plugin-scaffolder-backendto a version that resolves this vulnerability.Fixed in 3.1.1 - Upgrade
Upgrade
@backstage/plugin-scaffolder-nodeto a version that resolves this vulnerability.Fixed in 0.11.2 - Upgrade
Upgrade
@backstage/plugin-scaffolder-nodeto a version that resolves this vulnerability.Fixed in 0.12.3 - Compensating control
Follow the Backstage Threat Model recommendation to limit access to creating and updating Scaffolder templates, restrict who can create and execute Scaffolder templates using the permissions framework, audit existing templates for symlink usage, and/or run Backstage in a containerized environment with limited filesystem access.
Event History
Frequently Asked Questions
Who is exposed to exploitation?
Any Backstage deployment in which users can create or execute Scaffolder templates is affected. An attacker needs access to create and execute a template to use the vulnerable actions or archive extraction paths.
What impact can a successful attacker have?
A malicious template can use symlinks to read arbitrary files through the debug:log action, delete files outside the workspace through fs:delete, or write files outside the workspace through crafted tar or zip archive extraction.
Which package versions contain fixes?
Fixed versions are @backstage/backend-defaults 0.12.2, 0.13.2, 0.14.1, and 0.15.0; @backstage/plugin-scaffolder-backend 2.2.2, 3.0.2, and 3.1.1; and @backstage/plugin-scaffolder-node 0.11.2 and 0.12.3. Upgrade to the applicable listed version or later.
What can be done if upgrading is not immediately possible?
Limit access to creating and updating templates, and restrict who can create and execute Scaffolder templates, following the Backstage Threat Model recommendations.