CVE-2023-35926
CVSS Score of 10 (low)
Details
Summary
CVE-2023-35926 is a vulnerability that affects the Backstage scaffolder-backend plugin used to build developer portals. The plugin previously used a sandbox library called `vm2`, which had known vulnerabilities, so it has now been switched to a different sandbox library. The vulnerability allows a malicious actor with write access to a registered scaffolder template to manipulate the template in a way that enables remote code execution on the scaffolder-backend instance. This vulnerability is only exploitable in the template YAML definition and not through user input data. The issue has been fixed in version 1.15.0 of `@backstage/plugin-scaffolder-backend`. The potential danger posed by this vulnerability is high, as it could allow an attacker to execute arbitrary code on the affected system, leading to unauthorized access and potential data breaches.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Advisories, Assessments, and Mitigations
Prioritize, Pinpoint, and Act to Prevent Vulnerability Exploits with Recorded Future
- Gain complete coverage of your cyber, third party, and physical attack surface
- Proactively mitigate threats before they turn into costly attacks
- Make fast, effective, data-driven decisions