Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-46976

Опубликовано: 17 сент. 2024
Источник: nvd
CVSS3: 6.5
CVSS3: 5.4
EPSS Низкий

Описание

Backstage is an open framework for building developer portals. An attacker with control of the contents of the TechDocs storage buckets is able to inject executable scripts in the TechDocs content that will be executed in the victim's browser when browsing documentation or navigating to an attacker provided link. This has been fixed in the 1.10.13 release of the @backstage/plugin-techdocs-backend package. users are advised to upgrade. There are no known workarounds for this vulnerability.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:linuxfoundation:backstage:*:*:*:*:*:*:*:*
Версия до 1.10.13 (исключая)

EPSS

Процентиль: 23%
0.00075
Низкий

6.5 Medium

CVSS3

5.4 Medium

CVSS3

Дефекты

CWE-693
CWE-79

Связанные уязвимости

CVSS3: 5.4
redhat
больше 1 года назад

Backstage is an open framework for building developer portals. An attacker with control of the contents of the TechDocs storage buckets is able to inject executable scripts in the TechDocs content that will be executed in the victim's browser when browsing documentation or navigating to an attacker provided link. This has been fixed in the 1.10.13 release of the `@backstage/plugin-techdocs-backend` package. users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS3: 6.5
github
больше 1 года назад

@backstage/plugin-techdocs-backend vulnerable to circumvention of cross site scripting protection

CVSS3: 6.5
fstec
больше 1 года назад

Уязвимость модуля TechDocs платформы для построения порталов разработчиков Backstage, позволяющая нарушителю проводить межсайтовые сценарные атаки

EPSS

Процентиль: 23%
0.00075
Низкий

6.5 Medium

CVSS3

5.4 Medium

CVSS3

Дефекты

CWE-693
CWE-79