Junglewise Threat Intelligence

CVE-2024-46976: Backstage TechDocs plugin XSS circumvention via storage bucket injection

CVE-2024-46976 · Severity: low · CVSS 3.1 · Published 2024-09-17

Vendors: npm, Backstage.

Executive brief

Backstage is an open-source developer portal framework, and its TechDocs plugin automatically renders technical documentation. An attacker who gains control of the storage bucket containing TechDocs files can inject malicious scripts into documentation that execute in users' browsers when viewing the docs. This could lead to session hijacking, credential theft, or other client-side attacks against users accessing the documentation.

Technical details

The vulnerability is a cross-site scripting (XSS) protection circumvention (CWE-79, CWE-693) in the @backstage/plugin-techdocs-backend component. An attacker with write access to the TechDocs storage buckets can craft malicious documentation files containing embedded executable JavaScript. When legitimate users browse the documentation via the TechDocs frontend, the attacker-controlled scripts execute in their browser context. The attack requires authentication to the Backstage instance (PR:L) and user interaction (UI:R) to view the documentation. Impact is measured as low for confidentiality, integrity, and availability on a per-user basis, though scope is changed (affecting the user's browser session and potentially other browser-accessible resources). The patch was released in version 1.10.13 of the @backstage/plugin-techdocs-backend package.

Affected products

  • Backstage @backstage/plugin-techdocs-backend <1.10.13

Timeline

  • 2024-09-17: disclosed: Vulnerability published as GHSA-5j94-f3mf-8685 and CVE-2024-46976
  • 2024-09-17: patched: Fixed in @backstage/plugin-techdocs-backend version 1.10.13

References

Related threats