Executive brief
Backstage's scaffolder plugin allows users to create code projects from templates. A malicious actor with write access to templates can inject path traversal sequences to write files to arbitrary locations on the server, or exploit this through user input during template execution. This could lead to arbitrary file writes, potentially compromising the integrity of the scaffolder host and enabling further attacks.
Technical details
Path traversal vulnerability (CWE-22) in the @backstage/plugin-scaffolder-backend fetch:template action allows arbitrary file writes via manipulated template paths or unsanitized user input. Attackers with write access to registered scaffolder templates can craft payloads that bypass pathname restrictions, writing files to arbitrary locations on the host filesystem. The vulnerability can also be triggered through user input during template execution without template write access, though this method does not grant direct control over file contents unless the template is specifically crafted to allow it. The vulnerability affects versions prior to 0.15.14, which contains the fix.
Affected products
- Backstage plugin-scaffolder-backend < 0.15.14
Timeline
- 2021-11-29: disclosed
- 2021-12-01: patched: Version 0.15.14 released with fix