Backstage是一个应用软件。后台是一个开放的平台,用于构建开发者门户。 Backstage 1.10.13存在安全漏洞,该漏洞源于TechDocs存储桶内容受控于攻击者时,能够在TechDocs内容中注入可在受害者浏览器中执行的脚本,当用户浏览文档或导航到攻击者提供的链接时,脚本将会被执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-45816 | 6.5 MEDIUM | Storage bucket Directory Traversal in @backstage/plugin-techdocs-backend |
| CVE-2024-45815 | 6.5 MEDIUM | Prototype pollution in @backstage/plugin-catalog-backend |
No comments yet