Impact
An authenticated user who can execute an affected template and control its repository file location may cause generated content to be written outside the task workspace, within locations writable by the Backstage backend process.
Patches
Patched in @backstage/plugin-scaffolder-backend-module-confluence-to-markdown version 0.3.25
Workarounds
- Restrict execution of templates using the affected action to trusted users. - Remove or disable the affected action until the patched package is deployed.
Impact
Insufficient input validation in the Confluence to Markdown scaffolder module could allow an attacker to influence file write operations during template execution. Exploitation requires a Backstage user to run a template that processes attacker-influenced Confluence content.
Patches
Patched in @backstage/plugin-scaffolder-backend-module-confluence-to-markdown version 0.3.25
Workarounds
If unable to update immediately:
- Restrict Confluence edit access to trusted users. - Review Confluence page content before running scaffolder templates against untrusted pages.