Description
Backstage is an open framework for building developer portals. A malicious actor with authenticated access to a Backstage instance with the catalog backend plugin installed is able to interrupt the service using a specially crafted query to the catalog API. This has been fixed in the `1.26.0` release of the `@backstage/plugin-catalog-backend`. All users are advised to upgrade. There are no known workarounds for this vulnerability.
Published: 2024-09-17
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-2705 Backstage is an open framework for building developer portals. A malicious actor with authenticated access to a Backstage instance with the catalog backend plugin installed is able to interrupt the service using a specially crafted query to the catalog API. This has been fixed in the `1.26.0` release of the `@backstage/plugin-catalog-backend`. All users are advised to upgrade. There are no known workarounds for this vulnerability.
Github GHSA Github GHSA GHSA-3x3f-jcp3-g22j @backstage/plugin-catalog-backend Prototype Pollution vulnerability
History

Mon, 14 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00247}

epss

{'score': 0.00295}


Fri, 14 Feb 2025 02:30:00 +0000

Type Values Removed Values Added
First Time appeared Redhat
Redhat rhdh
CPEs cpe:/a:redhat:rhdh:1.4::el9
Vendors & Products Redhat
Redhat rhdh

Fri, 03 Jan 2025 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Linuxfoundation
Linuxfoundation backstage
CPEs cpe:2.3:a:backstage:backstage:*:*:*:*:*:*:*:* cpe:2.3:a:linuxfoundation:backstage:*:*:*:*:*:*:*:*
Vendors & Products Backstage
Backstage backstage
Linuxfoundation
Linuxfoundation backstage

Mon, 23 Sep 2024 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Backstage
Backstage backstage
CPEs cpe:2.3:a:backstage:backstage:*:*:*:*:*:*:*:*
Vendors & Products Backstage
Backstage backstage

Wed, 18 Sep 2024 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 18 Sep 2024 01:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Tue, 17 Sep 2024 20:30:00 +0000

Type Values Removed Values Added
Description Backstage is an open framework for building developer portals. A malicious actor with authenticated access to a Backstage instance with the catalog backend plugin installed is able to interrupt the service using a specially crafted query to the catalog API. This has been fixed in the `1.26.0` release of the `@backstage/plugin-catalog-backend`. All users are advised to upgrade. There are no known workarounds for this vulnerability.
Title Prototype pollution in @backstage/plugin-catalog-backend
Weaknesses CWE-1321
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Linuxfoundation Backstage
Redhat Rhdh
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-09-18T14:49:10.507Z

Reserved: 2024-09-09T14:23:07.506Z

Link: CVE-2024-45815

cve-icon Vulnrichment

Updated: 2024-09-18T14:49:06.483Z

cve-icon NVD

Status : Analyzed

Published: 2024-09-17T21:15:12.320

Modified: 2025-01-03T14:53:06.053

Link: CVE-2024-45815

cve-icon Redhat

Severity : Moderate

Publid Date: 2024-09-17T21:15:12Z

Links: CVE-2024-45815 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses