{"id":"GHSA-2g8g-63j4-9w3r","aliases":[],"url":"https://o3.security/vulnerability/GHSA-2g8g-63j4-9w3r","summary":"RCE vulnerability affecting v1beta3 templates in @backstage/plugin-scaffolder-backend","details":"The templating library used by the scaffolder backend assumes that templates are trusted which is an undesired property of the scaffolder-backend. This has now been mitigated by sandboxing the template code execution.\n\n### Impact\nA malicious actor with write access to a registered scaffolder template could manipulate the template in a way that allows for remote code execution on the scaffolder-backend instance. This was only exploitable in the template yaml definition itself and not by user input data.\n\n### Patches\nThis is vulnerability is patched in version `0.15.14` of `@backstage/plugin-scaffolder-backend`.\n\n\n### For more information\nIf you have any questions or comments about this advisory:\n\n* Open an issue in the [Backstage repository](https://github.com/backstage/backstage)\n* Visit our chat, linked to in [Backstage README](https://github.com/backstage/backstage)","published":"2021-12-01T18:29:12Z","modified":"2021-11-29T19:39:57Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@backstage/plugin-scaffolder-backend","fixedVersion":"0.15.14"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/backstage/backstage/security/advisories/GHSA-2g8g-63j4-9w3r"},{"type":"PACKAGE","url":"https://github.com/backstage/backstage"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2021-11-29T19:39:57Z"}}