{"id":"GHSA-4jqc-jvh2-pxg9","aliases":[],"url":"https://o3.security/vulnerability/GHSA-4jqc-jvh2-pxg9","summary":"Path traversal for local publishers in TechDocs backend","details":"### Impact\nA malicious actor with the ability to register entities in the Software Catalog is able to write files to arbitrary paths on the techdocs backend host instance when `techdocs.publisher.type` is set to `local`.\n\nThis vulnerability is mitigated by the fact that the Software Catalog must be configured with non-standard field format validators and/or non-standard entity policies.\n\n### Patches\nThose affected are advised to upgrade to `@backstage/plugin-techdocs-node` version `1.1.2` or higher.\n\n### Workarounds\nIf patching or upgrading is not possible, it would be sufficient to update any custom Catalog field format validators and/or custom entity policies to disallow entity names, kinds, and namespaces containing `..`\n\n<!--\n### References\ntodo: Link to blog post / published report.\n-->\n\n### For more information\nIf you have any questions or comments about this advisory:\n\n- Open an issue in the [Backstage repository](https://github.com/backstage/backstage)\n- Visit our chat, linked to in the [Backstage README](https://github.com/backstage/backstage)","published":"2022-06-17T01:11:10Z","modified":"2022-06-17T01:11:10Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@backstage/plugin-techdocs-node","fixedVersion":"1.1.2"},{"ecosystem":"npm","name":"@backstage/techdocs-common","fixedVersion":"0.11.16"}],"fix":{"url":"https://github.com/backstage/backstage/commit/429c9f9daa5654dd1b996aa85f7264eb23a2e4fa","label":"backstage/backstage@429c9f9"},"references":[{"type":"WEB","url":"https://github.com/backstage/backstage/security/advisories/GHSA-4jqc-jvh2-pxg9"},{"type":"WEB","url":"https://github.com/backstage/backstage/commit/429c9f9daa5654dd1b996aa85f7264eb23a2e4fa"},{"type":"PACKAGE","url":"https://github.com/backstage/backstage"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2022-06-17T01:11:10Z"}}