Vulnerability library
Security checkJanuary 12, 2023

Path traversal for local publishers in TechDocs backend

Understand the exposure, see the recommended fix, and check whether your own website has related weaknesses.

Check your website

Find this and other vulnerabilities with a free scan.

Your scan runs on your computer. No account required.

Description

A malicious actor with the ability to register entities in the Software Catalog is able to write files to arbitrary paths on the techdocs backend host instance when techdocs.publisher.type is set to local.

Recommendation

Update the @backstage/techdocs-common package to the latest compatible version. Followings are version details:

  • Affected version(s): < 0.11.16
  • Patched version(s): 0.11.16

References

Could your website be exposed too?

SmartScanner can check your website for Path traversal for local publishers in TechDocs backend and gives you actionable findings to investigate.

Start a free scan

Related Issues

See something that needs correcting? Let us knowUpdated January 12, 2023