PT-2021-19839 · Unknown · @Backstage/Plugin-Techdocs

Rugvip

·

Published

2021-06-03

·

Updated

2021-06-21

·

CVE-2021-32661

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions @backstage/plugin-techdocs versions prior to 0.9.5
Description A malicious internal actor can potentially upload documentation content with malicious scripts by embedding the script within an object element. This may give access to sensitive data when other users visit that same documentation page. The ability to upload malicious content may be limited by internal code review processes, unless the chosen TechDocs deployment method is to use an object store and the actor has access to upload files directly to that store.
Recommendations For versions prior to 0.9.5, update to the 0.9.5 release of @backstage/plugin-techdocs to patch the vulnerability. As a temporary workaround, consider restricting access to upload files directly to the object store and implementing strict internal code review processes to minimize the risk of exploitation.

Fix

Command Injection

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-32661
GHSA-GG96-F8WR-P89F

Affected Products

@Backstage/Plugin-Techdocs