Unexpected visibility of environment variable configurations in @backstage/plugin-app-backend
Published Oct 3, 2024
6.9
MEDIUMCVSS 4.0
EPSS 0.38%
Description
Backstage is an open framework for building developer portals. Configuration supplied through APP_CONFIG_* environment variables, for example APP_CONFIG_backend_listen_port=7007, where unexpectedly ignoring the visibility defined in configuration schema. This occurred even if the configuration schema specified that they should have backend or secret visibility. This was an intended feature of the APP_CONFIG_* way of supplying configuration, but now clearly goes against the expected behavior of the configuration system. This behavior leads to a risk of potentially exposing sensitive configuration details intended to remain private or restricted to backend processes. The issue has been resolved in version 0.3.75 of the @backstage/plugin-app-backend package. As a temporary measure, avoid supplying secrets using the APP_CONFIG_ configuration pattern. Consider alternative methods for setting secrets, such as the environment substitution available for Backstage configuration.
Affected products
-
- Version < 0.3.75StatusaffectedConstraints-
- Version
No data.
-
- Version 0StatusaffectedConstraints<0.3.75
- Version
Red Hat Developer Hub (RHDH) 1.4
rhdh/rhdh-hub-rhel9:1.4-1734106454
Fixed · RHBA-2024:11265
Red Hat Developer Hub
rhdh-operator-container
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Developer Hub (RHDH) 1.4 | rhdh/rhdh-hub-rhel9:1.4-1734106454 | Fixed | RHBA-2024:11265 |
| Red Hat Developer Hub | rhdh-operator-container | Not affected | n/a |
@backstage/plugin-app-backend
npm
Introduced 0 Fixed 0.3.75
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | @backstage/plugin-app-backend | 0 | 0.3.75 |
Remediation
Red Hat mitigation
Avoid supplying secrets using the APP_CONFIG_* configuration pattern. Consider alternative methods such as the environment variable substitution. See this link for more information about environment variable substitution: https://backstage.io/docs/conf/writing/#environment-variable-substitution
References (7)
- https://access.redhat.com/security/cve/CVE-2024-47762 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2316342 Issue Tracking
- https://github.com/advisories/GHSA-qc4v-xq2m-65wc Advisory
- https://github.com/backstage/backstage/commit/323e6129073c5cb4cc106a1239eaec31a129554f x_refsource_MISC
- https://github.com/backstage/backstage/security/advisories/GHSA-qc4v-xq2m-65wc x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2024-47762
- https://www.cve.org/CVERecord?id=CVE-2024-47762
Change history (0)
No recorded changes yet.