PT-2021-19839 · Unknown · @Backstage/Plugin-Techdocs
Rugvip
·
Published
2021-06-03
·
Updated
2021-06-21
·
CVE-2021-32661
CVSS v3.1
7.3
High
| Vector | AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
@backstage/plugin-techdocs versions prior to 0.9.5
Description
A malicious internal actor can potentially upload documentation content with malicious scripts by embedding the script within an
object element. This may give access to sensitive data when other users visit that same documentation page. The ability to upload malicious content may be limited by internal code review processes, unless the chosen TechDocs deployment method is to use an object store and the actor has access to upload files directly to that store.Recommendations
For versions prior to 0.9.5, update to the 0.9.5 release of @backstage/plugin-techdocs to patch the vulnerability. As a temporary workaround, consider restricting access to upload files directly to the object store and implementing strict internal code review processes to minimize the risk of exploitation.
Fix
Command Injection
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
@Backstage/Plugin-Techdocs