CVE-2024-26150
`@backstage/backend-common` vulnerable to path traversal through symlinks
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
`@backstage/backend-common` is a common functionality library for backends for Backstage, an open platform for building developer portals. In `@backstage/backend-common` prior to versions 0.21.1, 0.20.2, and 0.19.10, paths checks with the `resolveSafeChildPath` utility were not exhaustive enough, leading to risk of path traversal vulnerabilities if symlinks can be injected by attackers. This issue is patched in `@backstage/backend-common` versions 0.21.1, 0.20.2, and 0.19.10.
`@backstage/backend-common` es una librería de funcionalidad común para backends de Backstage, una plataforma abierta para crear portales de desarrolladores. En `@backstage/backend-common` anterior a las versiones 0.21.1, 0.20.2 y 0.19.10, las comprobaciones de rutas con la utilidad `resolveSafeChildPath` no eran lo suficientemente exhaustivas, lo que generaba riesgo de vulnerabilidades de path traversal si se podían inyectar enlaces simbólicos. por los atacantes. Este problema se solucionó en las versiones `@backstage/backend-common` 0.21.1, 0.20.2 y 0.19.10.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2024-02-14 CVE Reserved
- 2024-02-23 CVE Published
- 2024-02-24 EPSS Updated
- 2024-08-01 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
https://github.com/backstage/backstage/commit/1ad2b1b61ebb430051f7d804b0cc7ebfe7922b6f | X_refsource_misc | |
https://github.com/backstage/backstage/commit/78f892b3a84d63de2ba167928f171154c447b717 | X_refsource_misc | |
https://github.com/backstage/backstage/commit/edf65d7d31e027599c2415f597d085ee84807871 | X_refsource_misc | |
https://github.com/backstage/backstage/security/advisories/GHSA-2fc9-xpp8-2g9h | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Backstage Search vendor "Backstage" | Backstage Search vendor "Backstage" for product "Backstage" | 0.21.0 Search vendor "Backstage" for product "Backstage" and version "0.21.0" | en |
Affected
| ||||||
Backstage Search vendor "Backstage" | Backstage Search vendor "Backstage" for product "Backstage" | < 0.19.10 Search vendor "Backstage" for product "Backstage" and version " < 0.19.10" | en |
Affected
| ||||||
Backstage Search vendor "Backstage" | Backstage Search vendor "Backstage" for product "Backstage" | >= 0.20.0 < 0.20.2 Search vendor "Backstage" for product "Backstage" and version " >= 0.20.0 < 0.20.2" | en |
Affected
|