Bug 2312954 (CVE-2024-46976) - CVE-2024-46976 plugin-techdocs-backend: circumvention of XSS protection in TechDocs
Summary: CVE-2024-46976 plugin-techdocs-backend: circumvention of XSS protection in Te...
Keywords:
Status: NEW
Alias: CVE-2024-46976
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2024-09-17 21:20 UTC by OSIDB Bzimport
Modified: 2024-09-20 20:10 UTC (History)
6 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2024-09-17 21:20:35 UTC
Backstage is an open framework for building developer portals. An attacker with control of the contents of the TechDocs storage buckets is able to inject executable scripts in the TechDocs content that will be executed in the victim's browser when browsing documentation or navigating to an attacker provided link. This has been fixed in the 1.10.13 release of the `@backstage/plugin-techdocs-backend` package. users are advised to upgrade. There are no known workarounds for this vulnerability.


Note You need to log in before you can comment on or make changes to this bug.