Impact
Paths checks with the resolveSafeChildPath
utility were not exhaustive enough, leading to risk of path traversal vulnerabilities if symlinks can be injected by attackers.
Patches
Patched in @backstage/backend-common
version 0.21.1
.
Patched in @backstage/backend-common
version 0.20.2
.
Patched in @backstage/backend-common
version 0.19.10
.
For more information
If you have any questions or comments about this advisory:
Impact
Paths checks with the
resolveSafeChildPath
utility were not exhaustive enough, leading to risk of path traversal vulnerabilities if symlinks can be injected by attackers.Patches
Patched in
@backstage/backend-common
version0.21.1
.Patched in
@backstage/backend-common
version0.20.2
.Patched in
@backstage/backend-common
version0.19.10
.For more information
If you have any questions or comments about this advisory: