Executive brief
Backstage is an open platform used by organizations to build internal developer portals. A security flaw in a core library could allow an attacker with high-level permissions to bypass directory restrictions by using symbolic links. This could lead to unauthorized access to sensitive files or the modification of system data, potentially compromising the integrity of the developer portal.
Technical details
A path traversal vulnerability exists in the `resolveSafeChildPath` utility within the `@backstage/backend-common` package. The root cause is an non-exhaustive path validation check that fails to properly account for symbolic links (symlinks) injected by an attacker. If an attacker can create or influence symlinks within the file system, they can bypass intended directory restrictions to read or write files outside of the designated child path. Exploitation typically requires high privileges to inject the necessary symlinks but can result in a scope change affecting the host system. The issue is addressed by ensuring both the base and target paths are fully resolved before comparison.
Affected products
- Backstage @backstage/backend-common < 0.19.10, >= 0.20.0 < 0.20.2, 0.21.0
Timeline
- 2024-02-23: disclosed
- 2024-02-23: advisory
- 2024-02-23: patched
References
- https://github.com/backstage/backstage/security/advisories/GHSA-2fc9-xpp8-2g9h
- https://github.com/backstage/backstage/commit/1ad2b1b61ebb430051f7d804b0cc7ebfe7922b6f
- https://github.com/backstage/backstage/commit/78f892b3a84d63de2ba167928f171154c447b717
- https://github.com/backstage/backstage/commit/edf65d7d31e027599c2415f597d085ee84807871
- https://github.com/backstage/backstage