{"id":"GHSA-2g8g-63j4-9w3r","summary":"RCE vulnerability affecting v1beta3 templates in @backstage/plugin-scaffolder-backend","details":"The templating library used by the scaffolder backend assumes that templates are trusted which is an undesired property of the scaffolder-backend. This has now been mitigated by sandboxing the template code execution.\n\n### Impact\nA malicious actor with write access to a registered scaffolder template could manipulate the template in a way that allows for remote code execution on the scaffolder-backend instance. This was only exploitable in the template yaml definition itself and not by user input data.\n\n### Patches\nThis is vulnerability is patched in version `0.15.14` of `@backstage/plugin-scaffolder-backend`.\n\n\n### For more information\nIf you have any questions or comments about this advisory:\n\n* Open an issue in the [Backstage repository](https://github.com/backstage/backstage)\n* Visit our chat, linked to in [Backstage README](https://github.com/backstage/backstage)","modified":"2021-11-29T19:39:57Z","published":"2021-12-01T18:29:12Z","database_specific":{"cwe_ids":[],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2021-11-29T19:39:57Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://github.com/backstage/backstage/security/advisories/GHSA-2g8g-63j4-9w3r"},{"type":"PACKAGE","url":"https://github.com/backstage/backstage"}],"affected":[{"package":{"name":"@backstage/plugin-scaffolder-backend","ecosystem":"npm","purl":"pkg:npm/%40backstage/plugin-scaffolder-backend"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.15.14"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/12/GHSA-2g8g-63j4-9w3r/GHSA-2g8g-63j4-9w3r.json"}}],"schema_version":"1.9.0"}