CVE-2021-32662: Path Traversal
(updated )
Backstage is an open platform for building developer portals, and techdocs-common contains common functionalities for Backstage’s TechDocs. In @backstage/techdocs-common
, a malicious actor could read sensitive files from the environment where TechDocs documentation is built and published by setting a particular path for docs_dir
in mkdocs.yml
.
References
Detect and mitigate CVE-2021-32662 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →