Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-29184

Опубликовано: 07 мар. 2026
Источник: redhat
CVSS3: 2

Описание

Backstage is an open framework for building developer portals. Prior to version 3.1.4, a malicious scaffolder template can bypass the log redaction mechanism to exfiltrate secrets provided run through task event logs. This issue has been patched in version 3.1.4.

A flaw was found in @backstage/plugin-scaffolder-backend. A malicious scaffolder template can bypass the log redaction mechanism, allowing an attacker to exfiltrate sensitive information (secrets) from task event logs. This vulnerability leads to information disclosure, potentially exposing confidential data.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Developer Hubrhdh/rhdh-hub-rhel9Fix deferred
Self-service automation portal 2ansible-automation-platform/automation-portalFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-117
https://bugzilla.redhat.com/show_bug.cgi?id=2445468@backstage/plugin-scaffolder-backend: Backstage Scaffolder Backend: Information disclosure via malicious template bypassing log redaction

2 Low

CVSS3

Связанные уязвимости

CVSS3: 2
nvd
20 дней назад

Backstage is an open framework for building developer portals. Prior to version 3.1.4, a malicious scaffolder template can bypass the log redaction mechanism to exfiltrate secrets provided run through task event logs. This issue has been patched in version 3.1.4.

CVSS3: 2
github
23 дня назад

@backstage/plugin-scaffolder-backend Vulnerable to Potential Session Token Exfiltration via Log Redaction Bypass

2 Low

CVSS3