PT-2021-23930 · Unknown · @Backstage/Plugin-Scaffolder-Backend

Rugvip

·

Published

2021-11-29

·

Updated

2025-01-03

·

CVE-2021-43783

CVSS v3.1

8.5

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:L
Name of the Vulnerable Software and Affected Versions: @backstage/plugin-scaffolder-backend versions prior to 0.15.14
Description: A malicious actor with write access to a registered scaffolder template can manipulate the template to write files to arbitrary paths on the scaffolder-backend host instance. This issue can also be exploited through user input when executing a template, although this method does not allow control of the injected file's contents unless the template is specifically crafted to provide such control.
Recommendations: For versions prior to 0.15.14, update to version 0.15.14 to resolve the issue. As a temporary workaround, consider restricting access and requiring reviews when registering or modifying scaffolder templates to mitigate the attack.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2021-43783
GHSA-MG3M-F475-28HV

Affected Products

@Backstage/Plugin-Scaffolder-Backend