CVE-2023-35926

CVSS Score of 10 (low)

Details

Published Jun 22, 2023
Updated: Jun 29, 2023
CWE ID 94

Summary

CVE-2023-35926 is a vulnerability that affects the Backstage scaffolder-backend plugin used to build developer portals. The plugin previously used a sandbox library called `vm2`, which had known vulnerabilities, so it has now been switched to a different sandbox library. The vulnerability allows a malicious actor with write access to a registered scaffolder template to manipulate the template in a way that enables remote code execution on the scaffolder-backend instance. This vulnerability is only exploitable in the template YAML definition and not through user input data. The issue has been fixed in version 1.15.0 of `@backstage/plugin-scaffolder-backend`. The potential danger posed by this vulnerability is high, as it could allow an attacker to execute arbitrary code on the affected system, leading to unauthorized access and potential data breaches.

Share

Explore Beyond the CVE Basics with Recorded Future's Vulnerability Intelligence

Note: This is just a basic overview providing quick insights into CVE-2023-35926 information. Gain full access to comprehensive CVE data, risk scores, prioritization, and mitigation data through Recorded Future's Vulnerability Intelligence:
  • Prioritize with Risk-Based Scoring
  • Explore the Extensive Vulnerability Database
  • Receive Early Alerts on Emerging CVEs
  • Focus on Critical Exploitable Vulnerabilities
  • Streamline Remediation with Integration Options