Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
64 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.4) | 0.37% | — | Backstage Plugin-scaffolder-nodeAI | 29/11/2024 | 17/6/2026 | The Backstage Scaffolder plugin Houses types and utilities for building scaffolder-related modules. A vulnerability is identified in Backstage Scaffolder template functionality where Server-Side Template Injection (SSTI) can be exploited to perform Git config injection. The vulnerability allows an attacker to capture… | |
| Aplazada | Media (5.8) | 0.38% | — | Backstage Plugin-app-backendAI | 3/10/2024 | 17/6/2026 | Backstage is an open framework for building developer portals. Configuration supplied through APP_CONFIG_* environment variables, for example APP_CONFIG_backend_listen_port=7007, where unexpectedly ignoring the visibility defined in configuration schema. This occurred even if the configuration schema specified that… | |
| Analizada | Media (5.4) | 0.29% | — | Linuxfoundation Backstage | 17/9/2024 | 17/6/2026 | Backstage is an open framework for building developer portals. An attacker with control of the contents of the TechDocs storage buckets is able to inject executable scripts in the TechDocs content that will be executed in the victim's browser when browsing documentation or navigating to an attacker provided link. This… | |
| Analizada | Media (6.5) | 0.73% | — | Linuxfoundation Backstage | 17/9/2024 | 17/6/2026 | Backstage is an open framework for building developer portals. When using the AWS S3 or GCS storage provider for TechDocs it is possible to access content in the entire storage bucket. This can leak contents of the bucket that are not intended to be accessible, as well as bypass permission checks in Backstage. This… | |
| Analizada | Media (6.5) | 0.51% | — | Linuxfoundation Backstage | 17/9/2024 | 17/6/2026 | Backstage is an open framework for building developer portals. A malicious actor with authenticated access to a Backstage instance with the catalog backend plugin installed is able to interrupt the service using a specially crafted query to the catalog API. This has been fixed in the `1.26.0` release of the… | |
| Analizada | Alta (7.5) | 0.80% | — | Linuxfoundation Backstage Backend-common | 23/2/2024 | 17/6/2026 | `@backstage/backend-common` is a common functionality library for backends for Backstage, an open platform for building developer portals. In `@backstage/backend-common` prior to versions 0.21.1, 0.20.2, and 0.19.10, paths checks with the `resolveSafeChildPath` utility were not exhaustive enough, leading to risk of… | |
| Modificada | Media (5.7) | 0.56% | — | Redhat RED HAT Developer HUBLinuxfoundation Backstage | 4/1/2024 | 17/6/2026 | A flaw was found in the Red Hat Developer Hub (RHDH). The catalog-import function leaks GitLab access tokens on the frontend when the base64 encoded GitLab token includes a newline at the end of the string. The sanitized error can display on the frontend, including the raw access token. Upon gaining access to this… | |
| Modificada | Crítica (9.9) | 1.9% | — | Linuxfoundation Backstage | 22/6/2023 | 17/6/2026 | Backstage is an open platform for building developer portals. The Backstage scaffolder-backend plugin uses a templating library that requires sandbox, as it by design allows for code injection. The library used for this sandbox so far has been `vm2`, but in light of several past vulnerabilities and existing… | |
| Modificada | Media (5.4) | 0.45% | — | Linuxfoundation Backstage Catalog-modelLinuxfoundation Backstage Core-componentsLinuxfoundation Backstage Plugin-catalog-backend | 14/2/2023 | 17/6/2026 | Backstage is an open platform for building developer portals. `@backstage/catalog-model` prior to version 1.2.0, `@backstage/core-components` prior to 0.12.4, and `@backstage/plugin-catalog-backend` prior to 1.7.2 are affected by a cross-site scripting vulnerability. This vulnerability allows a malicious actor with… | |
| Analizada | Alta (8.5) | 1.2% | — | Linuxfoundation Backstage | 29/11/2021 | 17/6/2026 | @backstage/plugin-scaffolder-backend is the backend for the default Backstage software templates. In affected versions a malicious actor with write access to a registered scaffolder template is able to manipulate the template in a way that writes files to arbitrary paths on the scaffolder-backend host instance. This… | |
| Modificada | Media (4.9) | 1.3% | — | Linuxfoundation Backstage | 18/10/2021 | 17/6/2026 | Backstage is an open platform for building developer portals. In affected versions A malicious actor could read sensitive files from the environment where Scaffolder Tasks are run. The attack is executed by crafting a custom Scaffolder template with a `github:publish:pull-request` action and a particular source path.… | |
| Modificada | Media (6.5) | 1.3% | — | Linuxfoundation Backstage | 3/6/2021 | 17/6/2026 | Backstage is an open platform for building developer portals, and techdocs-common contains common functionalities for Backstage's TechDocs. In `@backstage/techdocs-common` versions prior to 0.6.3, a malicious actor could read sensitive files from the environment where TechDocs documentation is built and published by… | |
| Modificada | Alta (7.3) | 1.2% | — | Linuxfoundation @backstage/plugin-techdocs | 3/6/2021 | 17/6/2026 | Backstage is an open platform for building developer portals. In versions of Backstage's Techdocs Plugin (`@backstage/plugin-techdocs`) prior to 0.9.5, a malicious internal actor can potentially upload documentation content with malicious scripts by embedding the script within an `object` element. This may give access… | |
| Modificada | Alta (8.1) | 1.3% | — | Linuxfoundation @backstage/techdocs-common | 3/6/2021 | 17/6/2026 | Backstage is an open platform for building developer portals, and techdocs-common contains common functionalities for Backstage's TechDocs. In versions of `@backstage/tehdocs-common` prior to 0.6.4, a malicious internal actor is able to upload documentation content with malicious scripts. These scripts would normally… |