Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2fc9-xpp8-2g9h

Опубликовано: 23 фев. 2024
Источник: github
Github: Прошло ревью
CVSS3: 8.7

Описание

@backstage/backend-common vulnerable to path traversal through symlinks

Impact

Paths checks with the resolveSafeChildPath utility were not exhaustive enough, leading to risk of path traversal vulnerabilities if symlinks can be injected by attackers.

Patches

Patched in @backstage/backend-common version 0.21.1. Patched in @backstage/backend-common version 0.20.2. Patched in @backstage/backend-common version 0.19.10.

For more information

If you have any questions or comments about this advisory:

Пакеты

Наименование

@backstage/backend-common

npm
Затронутые версииВерсия исправления

= 0.21.0

0.21.1

Наименование

@backstage/backend-common

npm
Затронутые версииВерсия исправления

< 0.19.10

0.19.10

Наименование

@backstage/backend-common

npm
Затронутые версииВерсия исправления

>= 0.20.0, < 0.20.2

0.20.2

EPSS

Процентиль: 59%
0.00385
Низкий

8.7 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 5.5
redhat
больше 1 года назад

`@backstage/backend-common` is a common functionality library for backends for Backstage, an open platform for building developer portals. In `@backstage/backend-common` prior to versions 0.21.1, 0.20.2, and 0.19.10, paths checks with the `resolveSafeChildPath` utility were not exhaustive enough, leading to risk of path traversal vulnerabilities if symlinks can be injected by attackers. This issue is patched in `@backstage/backend-common` versions 0.21.1, 0.20.2, and 0.19.10.

CVSS3: 8.7
nvd
больше 1 года назад

`@backstage/backend-common` is a common functionality library for backends for Backstage, an open platform for building developer portals. In `@backstage/backend-common` prior to versions 0.21.1, 0.20.2, and 0.19.10, paths checks with the `resolveSafeChildPath` utility were not exhaustive enough, leading to risk of path traversal vulnerabilities if symlinks can be injected by attackers. This issue is patched in `@backstage/backend-common` versions 0.21.1, 0.20.2, and 0.19.10.

EPSS

Процентиль: 59%
0.00385
Низкий

8.7 High

CVSS3

Дефекты

CWE-22