Vulnerabilities/

Path traversal for local publishers in TechDocs backend

Severity:
Medium

Description

A malicious actor with the ability to register entities in the Software Catalog is able to write files to arbitrary paths on the techdocs backend host instance when techdocs.publisher.type is set to local.

Recommendation

Update the @backstage/techdocs-common package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@backstage/techdocs-common
Anything's wrong? Let us know Last updated on January 12, 2023