PT-2024-9764 · Npm · @Backstage/Plugin-Catalog-Backend

Rugvip

·

Published

2024-09-09

·

Updated

2025-01-03

·

CVE-2024-45815

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions: @backstage/plugin-catalog-backend versions prior to 1.26.0
Description: A malicious actor with authenticated access to a Backstage instance with the catalog backend plugin installed can interrupt the service using a specially crafted query to the catalog API. This issue is related to an uncontrolled modification of object prototype attributes, which can be exploited by a remote attacker to cause a denial of service by sending a specially crafted API request.
Recommendations: For versions prior to 1.26.0, upgrade to the 1.26.0 release of the @backstage/plugin-catalog-backend package to fix the issue. As a temporary workaround, consider restricting access to the catalog API to minimize the risk of exploitation. There are no known workarounds for this issue other than upgrading to the fixed version.

Exploit

Fix

Prototype Pollution

Weakness Enumeration

Related Identifiers

BDU:2024-11510
CVE-2024-45815
GHSA-3X3F-JCP3-G22J

Affected Products

@Backstage/Plugin-Catalog-Backend