Intel

AIKIDO-2024-10134

@backstage/plugin-catalog-backend is vulnerable to Information Disclosure

Information Disclosure Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Jun 21, 2024

20

Low Risk

This Affects:

JS@backstage/plugin-catalog-backend
0.1.1 - 1.22.0
Fixed in 1.23.0
Are you affected? Scan for Free

TL;DR

Affected versions of @backstage/plugin-catalog-backend expose sensitive information through verbose error messages.

Who does this affect?

You are affected if you use a vulnerable version of @backstage/plugin-catalog-backend.

Background info

@backstage/plugin-catalog-backend is vulnerable to Information Disclosure in versions 0.1.1 - 1.22.0.

How to fix this

Upgrade @backstage/plugin-catalog-backend to a patch version.