GHSA-w7fj-336r-vw49

Suggest an improvement
Source
https://github.com/advisories/GHSA-w7fj-336r-vw49
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/12/GHSA-w7fj-336r-vw49/GHSA-w7fj-336r-vw49.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-w7fj-336r-vw49
Aliases
  • CVE-2021-43776
Published
2021-12-01T18:29:21Z
Modified
2023-11-08T04:07:11.630381Z
Severity
  • 7.4 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N CVSS Calculator
Summary
Cross-Site Scripting vulnerability in @backstage/plugin-auth-backend
Details

Impact

This vulnerability allows a malicious actor to trick another user into visiting a vulnerable URL that executes an XSS attack. This attack can potentially allow the attacker to exfiltrate access tokens or other secrets from the user's browser. The default CSP does prevent this attack, but it is expected that some deployments have these policies disabled due to incompatibilities.

Patches

This is vulnerability is patched in version 0.4.9 of @backstage/plugin-auth-backend.

For more information

If you have any questions or comments about this advisory:

Database specific
{
    "nvd_published_at": "2021-11-26T19:15:00Z",
    "github_reviewed_at": "2021-11-29T19:19:57Z",
    "severity": "HIGH",
    "github_reviewed": true,
    "cwe_ids": [
        "CWE-79"
    ]
}
References

Affected packages

npm / @backstage/plugin-auth-backend

Package

Name
@backstage/plugin-auth-backend
View open source insights on deps.dev
Purl
pkg:npm/%40backstage/plugin-auth-backend

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.4.9