Path traversal vulnerabilities in @backstage/backend-common prior to versions 0.21.1, 0.20.2, and 0.19.10
CVE-2024-26150
What is CVE-2024-26150?
@backstage/backend-common is a shared library used in Backstage, which is an open platform aimed at building developer portals. Prior to versions 0.21.1, 0.20.2, and 0.19.10, the library exhibited insufficient path checks through the utility resolveSafeChildPath. This inadequacy posed a risk for path traversal attacks, specifically when attackers could inject symbolic links into the system. Users of the affected versions should apply the available patches to mitigate this security issue effectively.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
backstage = 0.21.0 = 0.21.0
backstage < 0.19.10 < 0.19.10
backstage >= 0.20.0, < 0.20.2 < 0.20.0, 0.20.2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
