CVE-2024-26150

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
23/02/2024
Last modified:
05/02/2025

Description

`@backstage/backend-common` is a common functionality library for backends for Backstage, an open platform for building developer portals. In `@backstage/backend-common` prior to versions 0.21.1, 0.20.2, and 0.19.10, paths checks with the `resolveSafeChildPath` utility were not exhaustive enough, leading to risk of path traversal vulnerabilities if symlinks can be injected by attackers. This issue is patched in `@backstage/backend-common` versions 0.21.1, 0.20.2, and 0.19.10.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:linuxfoundation:backstage_backend-common:*:*:*:*:*:node.js:*:* 0.19.10 (excluding)
cpe:2.3:a:linuxfoundation:backstage_backend-common:*:*:*:*:*:node.js:*:* 0.20.0 (including) 0.20.2 (excluding)
cpe:2.3:a:linuxfoundation:backstage_backend-common:0.21.0:*:*:*:*:node.js:*:*