QID 997127

Date Published: 2024-02-06

QID 997127: NodeJs (Npm) Security Update for @backstage/backend-app-api (GHSA-86rg-pf4c-5grg)

A flaw was found in the Red Hat Developer Hub (RHDH). The catalog-import function leaks GitLab access tokens on the frontend when the base64 encoded GitLab token includes a newline at the end of the string. The sanitized error can display on the frontend, including the raw access token. Upon gaining access to this token and depending on permissions, an attacker could push malicious code to repositories, delete resources in Git, revoke or generate new keys, and sign code illegitimately.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Medium - 5.7 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution
    Refer to Github security advisory GHSA-86rg-pf4c-5grg for updates and patch information.
    Vendor References

    CVEs related to QID 997127

    Software Advisories
    Advisory ID Software Component Link
    GHSA-86rg-pf4c-5grg @backstage/backend-app-api URL Logo github.com/advisories/GHSA-86rg-pf4c-5grg