-
Notifications
You must be signed in to change notification settings - Fork 542
fix(deps): update dependency @backstage/plugin-scaffolder-node [security] #7350
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
fix(deps): update dependency @backstage/plugin-scaffolder-node [security] #7350
Conversation
11fba83 to
1ceab8b
Compare
1ceab8b to
3d0651d
Compare
3d0651d to
54584d9
Compare
54584d9 to
6dfe3d9
Compare
6dfe3d9 to
704df28
Compare
704df28 to
35b07ab
Compare
|
@awanlin seems like the update to the renovate config didn't work considering this was opened again (along with #7349 and #7348) 😅 taking a look at the Dependency Dashboard it seems like there aren't any vulnerability alerts being produced:
I think it's safe to assume that the OSV vulnerability alerts are the source of all the security related Renovate PRs, so I think this is what we need to disable for the Backstage packages. Update: if you expand 'More Information' there is a clear indicator that the source of this is the OSV vulnerability alerts 👍
|
35b07ab to
5bc22e8
Compare
5bc22e8 to
5c6c1ae
Compare
5c6c1ae to
51797dc
Compare
51797dc to
92fb4fc
Compare
92fb4fc to
2527095
Compare
2527095 to
bee5691
Compare
bee5691 to
0ea32cf
Compare
0ea32cf to
4751c19
Compare
4751c19 to
5cf3b38
Compare
5cf3b38 to
ee2021b
Compare
ee2021b to
347db26
Compare
347db26 to
09b77a5
Compare
09b77a5 to
5f0b2cd
Compare
5f0b2cd to
0e80da9
Compare
0e80da9 to
9610fe7
Compare
9610fe7 to
2a958af
Compare
2a958af to
6def19e
Compare
6def19e to
f28180d
Compare
f28180d to
0df1e1c
Compare
0df1e1c to
8181933
Compare
8181933 to
01b2ad1
Compare
…ity] Signed-off-by: Renovate Bot <[email protected]>
01b2ad1 to
ed51dc5
Compare
This PR contains the following updates:
0.12.2→0.12.30.11.1→0.11.2^0.10.0→^0.11.0Backstage has a Possible Symlink Path Traversal in Scaffolder Actions
CVE-2026-24046 / GHSA-rq6q-wr2q-7pgp
More information
Details
Impact
Multiple Scaffolder actions and archive extraction utilities were vulnerable to symlink-based path traversal attacks. An attacker with access to create and execute Scaffolder templates could exploit symlinks to:
debug:logaction by creating a symlink pointing to sensitive files (e.g.,/etc/passwd, configuration files, secrets)fs:deleteaction by creating symlinks pointing outside the workspaceThis affects any Backstage deployment where users can create or execute Scaffolder templates.
Patches
This vulnerability is fixed in the following package versions:
@backstage/backend-defaultsversion 0.12.2, 0.13.2, 0.14.1, 0.15.0@backstage/plugin-scaffolder-backendversion 2.2.2, 3.0.2, 3.1.1@backstage/plugin-scaffolder-nodeversion 0.11.2, 0.12.3Users should upgrade to these versions or later.
Workarounds
References
Severity
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:LReferences
This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).
Release Notes
backstage/backstage (@backstage/plugin-scaffolder-node)
v0.12.3Compare Source
Patch Changes
c641c14: Wrap some of the action logic withresolveSafeChildPathand improve symlink handling when fetching remote and local files27f9061: REwrite]872eb91: Upgradezod-to-json-schemato latest versionConfiguration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR has been generated by Renovate Bot.