Логотип exploitDog
bind:CVE-2024-26150
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-26150

Количество 3

Количество 3

redhat логотип

CVE-2024-26150

больше 1 года назад

`@backstage/backend-common` is a common functionality library for backends for Backstage, an open platform for building developer portals. In `@backstage/backend-common` prior to versions 0.21.1, 0.20.2, and 0.19.10, paths checks with the `resolveSafeChildPath` utility were not exhaustive enough, leading to risk of path traversal vulnerabilities if symlinks can be injected by attackers. This issue is patched in `@backstage/backend-common` versions 0.21.1, 0.20.2, and 0.19.10.

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2024-26150

больше 1 года назад

`@backstage/backend-common` is a common functionality library for backends for Backstage, an open platform for building developer portals. In `@backstage/backend-common` prior to versions 0.21.1, 0.20.2, and 0.19.10, paths checks with the `resolveSafeChildPath` utility were not exhaustive enough, leading to risk of path traversal vulnerabilities if symlinks can be injected by attackers. This issue is patched in `@backstage/backend-common` versions 0.21.1, 0.20.2, and 0.19.10.

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-2fc9-xpp8-2g9h

больше 1 года назад

`@backstage/backend-common` vulnerable to path traversal through symlinks

CVSS3: 8.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2024-26150

`@backstage/backend-common` is a common functionality library for backends for Backstage, an open platform for building developer portals. In `@backstage/backend-common` prior to versions 0.21.1, 0.20.2, and 0.19.10, paths checks with the `resolveSafeChildPath` utility were not exhaustive enough, leading to risk of path traversal vulnerabilities if symlinks can be injected by attackers. This issue is patched in `@backstage/backend-common` versions 0.21.1, 0.20.2, and 0.19.10.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-26150

`@backstage/backend-common` is a common functionality library for backends for Backstage, an open platform for building developer portals. In `@backstage/backend-common` prior to versions 0.21.1, 0.20.2, and 0.19.10, paths checks with the `resolveSafeChildPath` utility were not exhaustive enough, leading to risk of path traversal vulnerabilities if symlinks can be injected by attackers. This issue is patched in `@backstage/backend-common` versions 0.21.1, 0.20.2, and 0.19.10.

CVSS3: 8.7
0%
Низкий
больше 1 года назад
github логотип
GHSA-2fc9-xpp8-2g9h

`@backstage/backend-common` vulnerable to path traversal through symlinks

CVSS3: 8.7
0%
Низкий
больше 1 года назад

Уязвимостей на страницу