Backstage

Backstage

9 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.02%
  • Veröffentlicht 30.01.2026 21:51:22
  • Zuletzt bearbeitet 19.02.2026 15:37:56

Backstage is an open framework for building developer portals, and @backstage/plugin-techdocs-node provides common node.js functionalities for TechDocs. In versions of @backstage/plugin-techdocs-node prior to 1.13.11 and 1.14.1, a path traversal vuln...

  • EPSS 0.02%
  • Veröffentlicht 30.01.2026 21:31:58
  • Zuletzt bearbeitet 19.02.2026 15:26:37

Backstage is an open framework for building developer portals, and @backstage/plugin-techdocs-node provides common node.js functionalities for TechDocs. In versions of @backstage/plugin-techdocs-node prior to 1.13.11 and 1.14.1, when TechDocs is conf...

  • EPSS 0.03%
  • Veröffentlicht 21.01.2026 22:51:44
  • Zuletzt bearbeitet 26.01.2026 15:04:59

Backstage is an open framework for building developer portals, and @backstage/backend-defaults provides the default implementations and setup for a standard Backstage backend app. Prior to versions 0.12.2, 0.13.2, 0.14.1, and 0.15.0, the `FetchUrlRea...

  • EPSS 0.02%
  • Veröffentlicht 21.01.2026 22:45:06
  • Zuletzt bearbeitet 26.01.2026 15:04:59

Backstage is an open framework for building developer portals, and @backstage/cli-common provides config loading functionality used by the backend and command line interface of Backstage. Prior to version 0.1.17, the `resolveSafeChildPath` utility fu...

  • EPSS 0.02%
  • Veröffentlicht 21.01.2026 22:36:30
  • Zuletzt bearbeitet 26.01.2026 15:04:59

Backstage is an open framework for building developer portals. Multiple Scaffolder actions and archive extraction utilities were vulnerable to symlink-based path traversal attacks. An attacker with access to create and execute Scaffolder templates co...

  • EPSS 0.03%
  • Veröffentlicht 15.08.2025 17:10:26
  • Zuletzt bearbeitet 18.08.2025 20:16:28

@backstage/plugin-scaffolder-backend is the backend for the default Backstage software templates. Prior to version 2.1.1, duplicate logging of the input values in the fetch:template action in the Scaffolder meant that some of the secrets were not pro...

  • EPSS 0.2%
  • Veröffentlicht 16.04.2025 21:46:23
  • Zuletzt bearbeitet 17.04.2025 20:21:48

The Backstage Scaffolder plugin houses types and utilities for building scaffolder-related modules. A vulnerability in the Backstage permission plugin backend allows callers to extract some information about the conditional decisions returned by the ...

  • EPSS 0.07%
  • Veröffentlicht 29.11.2024 19:15:10
  • Zuletzt bearbeitet 29.11.2024 19:15:10

The Backstage Scaffolder plugin Houses types and utilities for building scaffolder-related modules. A vulnerability is identified in Backstage Scaffolder template functionality where Server-Side Template Injection (SSTI) can be exploited to perform G...

  • EPSS 0.19%
  • Veröffentlicht 03.10.2024 18:15:05
  • Zuletzt bearbeitet 04.10.2024 13:50:43

Backstage is an open framework for building developer portals. Configuration supplied through APP_CONFIG_* environment variables, for example APP_CONFIG_backend_listen_port=7007, where unexpectedly ignoring the visibility defined in configuration sch...