Insecure deserialization In @backstage/plugin-techdocs-node
Description
Backstage: Improper validation of TechDocs MkDocs configuration
Impact
An attacker who can provide configuration to a TechDocs build may execute code in the generator runtime. Impact is greatest when documentation generation runs with backend credentials or host access.
Patches
Patched in @backstage/plugin-techdocs-node version 1.15.4.
Workarounds
Use external TechDocs generation in an isolated environment without sensitive credentials or host access. Restrict and review changes to documentation configuration before generation.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
npm | 1.15.4 |
Aliases
1. 2. 3. 4. 5.
References
1. 2. 3. 4. 5. 6. 7.