CVE-2024-26150
CVSS 3.1 Score 8.7 of 10 (high)
Details
Published Feb 23, 2024
CWE ID 22
Summary
CVE-2024-26150 affects the `@backstage/backend-common` library used in Backstage, an open-source developer portal platform. Prior to versions 0.21.1, 0.20.2, and 0.19.10, this library contained insufficient path checks using the `resolveSafeChildPath` utility. Attackers who can inject symlinks can exploit this vulnerability to traverse paths, potentially leading to sensitive data exposure or unauthorized access. The issue has been addressed in subsequent releases of `@backstage/backend-common`.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share