Логотип exploitDog
bind:CVE-2024-45816
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-45816

Количество 4

Количество 4

redhat логотип

CVE-2024-45816

больше 1 года назад

Backstage is an open framework for building developer portals. When using the AWS S3 or GCS storage provider for TechDocs it is possible to access content in the entire storage bucket. This can leak contents of the bucket that are not intended to be accessible, as well as bypass permission checks in Backstage. This has been fixed in the 1.10.13 release of the `@backstage/plugin-techdocs-backend` package. All users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2024-45816

больше 1 года назад

Backstage is an open framework for building developer portals. When using the AWS S3 or GCS storage provider for TechDocs it is possible to access content in the entire storage bucket. This can leak contents of the bucket that are not intended to be accessible, as well as bypass permission checks in Backstage. This has been fixed in the 1.10.13 release of the `@backstage/plugin-techdocs-backend` package. All users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-39v3-f278-vj3g

больше 1 года назад

@backstage/plugin-techdocs-backend storage bucket Directory Traversal vulnerability

CVSS3: 7.7
EPSS: Низкий
fstec логотип

BDU:2024-11514

больше 1 года назад

Уязвимость модуля AWS S3 платформы для построения порталов разработчиков Backstage, позволяющая нарушителю обойти ограничения безопасности и получить несанкционированный доступ к защищаемой информации

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2024-45816

Backstage is an open framework for building developer portals. When using the AWS S3 or GCS storage provider for TechDocs it is possible to access content in the entire storage bucket. This can leak contents of the bucket that are not intended to be accessible, as well as bypass permission checks in Backstage. This has been fixed in the 1.10.13 release of the `@backstage/plugin-techdocs-backend` package. All users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-45816

Backstage is an open framework for building developer portals. When using the AWS S3 or GCS storage provider for TechDocs it is possible to access content in the entire storage bucket. This can leak contents of the bucket that are not intended to be accessible, as well as bypass permission checks in Backstage. This has been fixed in the 1.10.13 release of the `@backstage/plugin-techdocs-backend` package. All users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-39v3-f278-vj3g

@backstage/plugin-techdocs-backend storage bucket Directory Traversal vulnerability

CVSS3: 7.7
0%
Низкий
больше 1 года назад
fstec логотип
BDU:2024-11514

Уязвимость модуля AWS S3 платформы для построения порталов разработчиков Backstage, позволяющая нарушителю обойти ограничения безопасности и получить несанкционированный доступ к защищаемой информации

CVSS3: 6.5
0%
Низкий
больше 1 года назад

Уязвимостей на страницу