Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-25571

Опубликовано: 14 фев. 2023
Источник: nvd
CVSS3: 6.8
CVSS3: 5.4
EPSS Низкий

Описание

Backstage is an open platform for building developer portals. @backstage/catalog-model prior to version 1.2.0, @backstage/core-components prior to 0.12.4, and @backstage/plugin-catalog-backend prior to 1.7.2 are affected by a cross-site scripting vulnerability. This vulnerability allows a malicious actor with access to add or modify content in an instance of the Backstage software catalog to inject script URLs in the entities stored in the catalog. If users of the catalog then click on said URLs, that can lead to an XSS attack.

This vulnerability has been patched in both the frontend and backend implementations. The default Link component from @backstage/core-components version 1.2.0 and greater will now reject javascript: URLs, and there is a global override of window.open to do the same. In addition, the catalog model v0.12.4 and greater as well as the catalog backend v1.7.2 and greater now has additional validation built in that prevents javascript: URLs in known an

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:linuxfoundation:backstage_catalog-model:*:*:*:*:*:node.js:*:*
Версия до 1.2.0 (исключая)
cpe:2.3:a:linuxfoundation:backstage_core-components:*:*:*:*:*:node.js:*:*
Версия до 0.12.4 (исключая)
cpe:2.3:a:linuxfoundation:backstage_plugin-catalog-backend:*:*:*:*:*:node.js:*:*
Версия до 1.7.2 (исключая)

EPSS

Процентиль: 62%
0.00435
Низкий

6.8 Medium

CVSS3

5.4 Medium

CVSS3

Дефекты

CWE-79
CWE-79

Связанные уязвимости

CVSS3: 6.8
github
почти 3 года назад

Cross site scripting Vulnerability in backstage Software Catalog

EPSS

Процентиль: 62%
0.00435
Низкий

6.8 Medium

CVSS3

5.4 Medium

CVSS3

Дефекты

CWE-79
CWE-79