OSV 1.4.0 · github-reviewed · 修改于 2021-11-30 03:39
发布时间
2021-12-02 02:29
GitHub 审查时间
2021-11-30 03:39
NVD 发布时间
—
源文件
advisories/github-reviewed/2021/12/GHSA-2g8g-63j4-9w3r/GHSA-2g8g-63j4-9w3r.json
The templating library used by the scaffolder backend assumes that templates are trusted which is an undesired property of the scaffolder-backend. This has now been mitigated by sandboxing the template code execution.
A malicious actor with write access to a registered scaffolder template could manipulate the template in a way that allows for remote code execution on the scaffolder-backend instance. This was only exploitable in the template yaml definition itself and not by user input data.
This is vulnerability is patched in version 0.15.14 of @backstage/plugin-scaffolder-backend.
If you have any questions or comments about this advisory: