PT-2021-23925 · Backstage · @Backstage/Plugin-Auth-Backend
Jhaalsp
·
Published
2021-11-26
·
Updated
2021-12-01
·
CVE-2021-43776
CVSS v3.1
7.4
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
@backstage/plugin-auth-backend versions prior to 0.4.9
Description:
The auth-backend plugin in Backstage allows a malicious actor to trick another user into visiting a vulnerable URL that executes an XSS attack, potentially allowing the attacker to exfiltrate access tokens or other secrets from the user's browser. The default Content Security Policy (CSP) prevents this attack, but some deployments may have these policies disabled due to incompatibilities.
Recommendations:
For versions prior to 0.4.9, update to version 0.4.9 of @backstage/plugin-auth-backend to patch the vulnerability. As a temporary workaround, consider restricting access to the auth-backend plugin until the update is applied. Additionally, review and ensure that Content Security Policy (CSP) is enabled and properly configured to minimize the risk of exploitation.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
@Backstage/Plugin-Auth-Backend