VDB
Sign up
HIGH8.7

GHSA-2fc9-xpp8-2g9h

`@backstage/backend-common` vulnerable to path traversal through symlinks

Quick fix

GHSA-2fc9-xpp8-2g9h — @backstage/backend-common: upgrade to the fixed version with the command below.

npm install @backstage/backend-common@0.21.1

Details

### Impact

Paths checks with the `resolveSafeChildPath` utility were not exhaustive enough, leading to risk of path traversal vulnerabilities if symlinks can be injected by attackers.

### Patches Patched in `@backstage/backend-common` version `0.21.1`. Patched in `@backstage/backend-common` version `0.20.2`. Patched in `@backstage/backend-common` version `0.19.10`.

### For more information If you have any questions or comments about this advisory:

- Open an issue in the [Backstage repository](https://github.com/backstage/backstage) - Visit our Discord, linked to in [Backstage README](https://github.com/backstage/backstage)

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@backstage/backend-common
Introduced in: 0.21.0Fixed in: 0.21.1
Fixnpm install @backstage/backend-common@0.21.1
npm/@backstage/backend-common
Introduced in: 0Fixed in: 0.19.10
Fixnpm install @backstage/backend-common@0.19.10
npm/@backstage/backend-common
Introduced in: 0.20.0Fixed in: 0.20.2
Fixnpm install @backstage/backend-common@0.20.2

References