PT-2021-23930 · Unknown · @Backstage/Plugin-Scaffolder-Backend

·

CVE-2021-43783

·

Published

2021-11-29

·

Updated

2025-01-03

CVSS v3.1

8.5

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:L
Name of the Vulnerable Software and Affected Versions: @backstage/plugin-scaffolder-backend versions prior to 0.15.14
Description: A malicious actor with write access to a registered scaffolder template can manipulate the template to write files to arbitrary paths on the scaffolder-backend host instance. This issue can also be exploited through user input when executing a template, although this method does not allow control of the injected file's contents unless the template is specifically crafted to provide such control.
Recommendations: For versions prior to 0.15.14, update to version 0.15.14 to resolve the issue. As a temporary workaround, consider restricting access and requiring reviews when registering or modifying scaffolder templates to mitigate the attack.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-43783
GHSA-MG3M-F475-28HV

Affected Products

@Backstage/Plugin-Scaffolder-Backend