PT-2024-32800 · Unknown · @Backstage/Plugin-App-Backend

·

CVE-2024-47762

·

Published

2024-10-03

·

Updated

2024-10-04

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions @backstage/plugin-app-backend versions prior to 0.3.75
Description The issue concerns the configuration supplied through APP CONFIG * environment variables, where the visibility defined in the configuration schema is unexpectedly ignored. This behavior leads to a risk of potentially exposing sensitive configuration details intended to remain private or restricted to backend processes.
Recommendations For versions prior to 0.3.75, upgrade to version 0.3.75 of the @backstage/plugin-app-backend package to mitigate the issue. As a temporary measure, avoid supplying secrets using the APP CONFIG configuration pattern. Consider alternative methods for setting secrets, such as the environment substitution available for Backstage configuration.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-47762
GHSA-QC4V-XQ2M-65WC

Affected Products

@Backstage/Plugin-App-Backend