Vulnerabilities (CVE)

Filtered by vendor Linuxfoundation
Filtered by product \@backstage\/techdocs-common
Angry Yack Logo
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-32660 1 Linuxfoundation 1 \@backstage\/techdocs-common 2024-11-21 5.8 MEDIUM 6.8 MEDIUM
Backstage is an open platform for building developer portals, and techdocs-common contains common functionalities for Backstage's TechDocs. In versions of `@backstage/tehdocs-common` prior to 0.6.4, a malicious internal actor is able to upload documentation content with malicious scripts. These scripts would normally be sanitized by the TechDocs frontend, but by tricking a user to visit the content via the TechDocs API, the content sanitazion will be bypassed. If the TechDocs API is hosted on th ...

Show More