Junglewise Threat Intelligence

CVE-2024-53983: Backstage Scaffolder plugin server-side template injection and git token theft

CVE-2024-53983 · Severity: low · CVSS 3.1 · Published 2024-12-02

Vendors: Backstage.

Executive brief

The Backstage Scaffolder plugin, a component used to generate project templates within the Backstage developer platform, contains a server-side template injection vulnerability. An attacker with privileges to create or edit templates can exploit this flaw to inject malicious git configuration, allowing them to capture authentication tokens used by the plugin to access git repositories. These stolen tokens could then be used to gain unauthorized access to sensitive source code and other resources in git systems.

Technical details

The vulnerability is a Server-Side Template Injection (SSTI) flaw in Backstage Scaffolder template functionality that can be chained with Git config injection attacks. The @backstage/plugin-scaffolder-node package does not properly sanitize template input before processing, allowing an attacker with high privileges and the ability to create or edit templates to inject malicious template expressions. These expressions are evaluated server-side and can be used to modify git configuration to intercept and exfiltrate privileged git tokens. The attack requires high privilege level (template editor/admin access), user interaction, and a changed scope (affecting other components). The vulnerability has been patched in versions 0.4.12, 0.5.1, and 0.6.1. The risk is mitigated by the Backstage threat model's recommendation to restrict template access.

Affected products

  • Backstage @backstage/plugin-scaffolder-node <0.4.12, 0.5.0, 0.6.0

Timeline

  • 2024-11-29: disclosed
  • 2024-12-02: advisory: GHSA-qmc2-jpr5-7rg9 published; CVE-2024-53983 assigned
  • 2024-12-02: patched: Patches released in versions 0.4.12, 0.5.1, and 0.6.1

References