VDB
Sign up
MEDIUM

GHSA-4jqc-jvh2-pxg9

Path traversal for local publishers in TechDocs backend

Quick fix

GHSA-4jqc-jvh2-pxg9 — @backstage/plugin-techdocs-node: upgrade to the fixed version with the command below.

npm install @backstage/plugin-techdocs-node@1.1.2

Details

### Impact A malicious actor with the ability to register entities in the Software Catalog is able to write files to arbitrary paths on the techdocs backend host instance when `techdocs.publisher.type` is set to `local`.

This vulnerability is mitigated by the fact that the Software Catalog must be configured with non-standard field format validators and/or non-standard entity policies.

### Patches Those affected are advised to upgrade to `@backstage/plugin-techdocs-node` version `1.1.2` or higher.

### Workarounds If patching or upgrading is not possible, it would be sufficient to update any custom Catalog field format validators and/or custom entity policies to disallow entity names, kinds, and namespaces containing `..`

<!-- ### References todo: Link to blog post / published report. -->

### For more information If you have any questions or comments about this advisory:

- Open an issue in the [Backstage repository](https://github.com/backstage/backstage) - Visit our chat, linked to in the [Backstage README](https://github.com/backstage/backstage)

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@backstage/plugin-techdocs-node
Introduced in: 0Fixed in: 1.1.2
Fixnpm install @backstage/plugin-techdocs-node@1.1.2
npm/@backstage/techdocs-common
Introduced in: 0Fixed in: 0.11.16
Fixnpm install @backstage/techdocs-common@0.11.16

References