GHSA-3x3f-jcp3-g22j
@backstage/plugin-catalog-backend Prototype Pollution vulnerability
Quick fix
GHSA-3x3f-jcp3-g22j — @backstage/plugin-catalog-backend: upgrade to the fixed version with the command below.
npm install @backstage/plugin-catalog-backend@1.26.0Details
### Impact
A malicious actor with authenticated access to a Backstage instance with the catalog backend plugin installed is able to interrupt the service using a specially crafted query to the catalog API.
### Patches
This has been fixed in the `1.26.0` release of the `@backstage/plugin-catalog-backend` package.
### References
If you have any questions or comments about this advisory:
Open an issue in the [Backstage repository](https://github.com/backstage/backstage) Visit our Discord, linked to in [Backstage README](https://github.com/backstage/backstage)
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 1.26.0npm install @backstage/plugin-catalog-backend@1.26.0