Home
LOW: 2.0 CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:N < 3.1.4
affected
Description
Backstage is an open framework for building developer portals. Prior to version 3.1.4, a malicious scaffolder template can bypass the log redaction mechanism to exfiltrate secrets provided run through task event logs. This issue has been patched in version 3.1.4.
Problem types
CWE-532: Insertion of Sensitive Information into Log File
Product status
References
github.com/...kstage/security/advisories/GHSA-8qp7-fhr9-fw53