PT-2024-32800 · Unknown · @Backstage/Plugin-App-Backend

Rugvip

·

Published

2024-10-03

·

Updated

2024-10-04

·

CVE-2024-47762

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions @backstage/plugin-app-backend versions prior to 0.3.75
Description The issue concerns the configuration supplied through APP CONFIG * environment variables, where the visibility defined in the configuration schema is unexpectedly ignored. This behavior leads to a risk of potentially exposing sensitive configuration details intended to remain private or restricted to backend processes.
Recommendations For versions prior to 0.3.75, upgrade to version 0.3.75 of the @backstage/plugin-app-backend package to mitigate the issue. As a temporary measure, avoid supplying secrets using the APP CONFIG configuration pattern. Consider alternative methods for setting secrets, such as the environment substitution available for Backstage configuration.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2024-47762
GHSA-QC4V-XQ2M-65WC

Affected Products

@Backstage/Plugin-App-Backend