CVE-2023-35926

CVSS Score of 10 (low)

Details

Published Jun 22, 2023
Updated: Jun 29, 2023
CWE ID 94

Summary

CVE-2023-35926 is a vulnerability that affects the Backstage scaffolder-backend plugin used to build developer portals. The plugin previously used a sandbox library called `vm2`, which had known vulnerabilities, so it has now been switched to a different sandbox library. The vulnerability allows a malicious actor with write access to a registered scaffolder template to manipulate the template in a way that enables remote code execution on the scaffolder-backend instance. This vulnerability is only exploitable in the template YAML definition and not through user input data. The issue has been fixed in version 1.15.0 of `@backstage/plugin-scaffolder-backend`. The potential danger posed by this vulnerability is high, as it could allow an attacker to execute arbitrary code on the affected system, leading to unauthorized access and potential data breaches.

Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Prioritize, Pinpoint, and Act to Prevent Vulnerability Exploits with Recorded Future

Note: This is just a basic overview providing quick insights into CVE-2023-35926 information. Gain full access to comprehensive CVE data, third party vulnerabilities, compromised credentials and more with Recorded Future
  • Gain complete coverage of your cyber, third party, and physical attack surface
  • Proactively mitigate threats before they turn into costly attacks
  • Make fast, effective, data-driven decisions