VDB
Sign up
MEDIUM6.5

GHSA-3x3f-jcp3-g22j

@backstage/plugin-catalog-backend Prototype Pollution vulnerability

Quick fix

GHSA-3x3f-jcp3-g22j — @backstage/plugin-catalog-backend: upgrade to the fixed version with the command below.

npm install @backstage/plugin-catalog-backend@1.26.0

Details

### Impact

A malicious actor with authenticated access to a Backstage instance with the catalog backend plugin installed is able to interrupt the service using a specially crafted query to the catalog API.

### Patches

This has been fixed in the `1.26.0` release of the `@backstage/plugin-catalog-backend` package.

### References

If you have any questions or comments about this advisory:

Open an issue in the [Backstage repository](https://github.com/backstage/backstage) Visit our Discord, linked to in [Backstage README](https://github.com/backstage/backstage)

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@backstage/plugin-catalog-backend
Introduced in: 0Fixed in: 1.26.0
Fixnpm install @backstage/plugin-catalog-backend@1.26.0

References