CVE-2023-6944
@backstage/backend-app-api leaks GitLab access tokens
7.3
HIGH
CVSS 3.1
EPSS 0.22%
Description
A flaw was found in the Red Hat Developer Hub (RHDH). The catalog-import function leaks GitLab access tokens on the frontend when the base64 encoded GitLab token includes a newline at the end of the string. The sanitized error can display on the frontend, including the raw access token. Upon gaining access to this token and depending on permissions, an attacker could push malicious code to repositories, delete resources in Git, revoke or generate new keys, and sign code illegitimately.
How to fix CVE-2023-6944
To remediate CVE-2023-6944, upgrade the affected package to a fixed version below.
- —upgrade to 0.5.9-next.1 or later
Is CVE-2023-6944 being exploited?
Low — EPSS is 0.2%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 0.5.9-next.1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.3 | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N |