GHSA-2fc9-xpp8-2g9h
GitHub Security Advisory
`@backstage/backend-common` vulnerable to path traversal through symlinks
Advisory Details
### Impact
Paths checks with the `resolveSafeChildPath` utility were not exhaustive enough, leading to risk of path traversal vulnerabilities if symlinks can be injected by attackers.
### Patches
Patched in `@backstage/backend-common` version `0.21.1`.
Patched in `@backstage/backend-common` version `0.20.2`.
Patched in `@backstage/backend-common` version `0.19.10`.
### For more information
If you have any questions or comments about this advisory:
- Open an issue in the [Backstage repository](https://github.com/backstage/backstage)
- Visit our Discord, linked to in [Backstage README](https://github.com/backstage/backstage)
Affected Packages
Related CVEs
Key Information
Dataset
Data from GitHub Advisory Database. This information is provided for research and educational purposes.