Lack of data validation - Path Traversal In @backstage/plugin-proxy-backend
Description
Backstage: Improper input validation in proxy-backend
Impact
An authenticated Backstage user could craft a request URL that causes the proxy-backend to forward the request to a path outside the configured base path on the target server. This is limited to target servers already configured as proxy endpoints and requires Backstage authentication by default.
Patches
Patched in @backstage/plugin-proxy-backend version 0.6.17
Workarounds
Deploy a reverse proxy or WAF in front of Backstage that normalizes request paths before they reach the backend.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
npm | 0.6.17 |
Aliases
References