17 Nov, 2022

Remote Code Execution Error Reported on Spotify's Backstage Software Catalog and Developer Platform!

An unauthenticated RCE Vulnerability was discovered in Spotify's Backstage project. The vulnerability (CVSS score: 9.8) exploits a critical sandbox leak in vm2, a JavaScript sandbox library (Sandbreak) that was released in recent months.

What is Backstage Platform?

Backstage is an open source platform for building developer portals. It is also widely used by Spotify, American Ailrlenes, Netflix, Splunk…. It combines all infrastructure tools, services and documentation to create an end-to-end streamlined development environment.

About Vulnerability:

"An unauthenticated threat actor can execute arbitrary system commands in a Backstage application by exploiting a vm2 sandbox output in the Scaffolder core plugin," said the Oxeye (Application Security Firm) team. Shared:

According to Oxeye, the vulnerability is due to a tool called Backstage's software templates.

spotify-backstage-yazilimi
Oxeye developed a code block to run code by attacking the Scaffolder plugin and tested it on a local distribution. 

kod-blogu

The malicious code was injected into a modified function of that plugin's rendering engine, run in the context of a virtual machine, and triggered by a bug calling an undefined function.

The payload creates a CallSite object outside of the sandbox, allowing the attacker to execute arbitrary commands on the host system. You can go to the attack diagram available in the link.

Currently, the number of instances running Backstage versions prior to 1.5.1 is unknown.

As a result of this vulnerability, security administrators are advised to upgrade to the latest version of Backstage.

Source:

Spotify’ın Backstage Yazılım Kataloğu ve Geliştirici Platformunda Kritik RCE Hatası Bildirildi (thehackernews.com)

Araştırmacılar, Backstage ön kimlik doğrulama RCE hatası için istismar ayrıntılarını yayınladı (bleepingcomputer.com)

Oxeye (@OxeyeSecurity) / Twitter


To request a quotation for the following: Cyber Security, Digital Transformation, MSSP, Penetration Testing, KVKK, GDPR, ISO 27001 and ISO 27701, please click here.


 

About Content:
Share on Social Media:
Facebook
Twitter
LinkedIn
Telegram