Executive brief
Backstage is an open-source developer portal framework, and its TechDocs plugin automatically renders technical documentation. An attacker who gains control of the storage bucket containing TechDocs files can inject malicious scripts into documentation that execute in users' browsers when viewing the docs. This could lead to session hijacking, credential theft, or other client-side attacks against users accessing the documentation.
Technical details
The vulnerability is a cross-site scripting (XSS) protection circumvention (CWE-79, CWE-693) in the @backstage/plugin-techdocs-backend component. An attacker with write access to the TechDocs storage buckets can craft malicious documentation files containing embedded executable JavaScript. When legitimate users browse the documentation via the TechDocs frontend, the attacker-controlled scripts execute in their browser context. The attack requires authentication to the Backstage instance (PR:L) and user interaction (UI:R) to view the documentation. Impact is measured as low for confidentiality, integrity, and availability on a per-user basis, though scope is changed (affecting the user's browser session and potentially other browser-accessible resources). The patch was released in version 1.10.13 of the @backstage/plugin-techdocs-backend package.
Affected products
- Backstage @backstage/plugin-techdocs-backend <1.10.13
Timeline
- 2024-09-17: disclosed: Vulnerability published as GHSA-5j94-f3mf-8685 and CVE-2024-46976
- 2024-09-17: patched: Fixed in @backstage/plugin-techdocs-backend version 1.10.13