You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Hi, I would like to ask for upgrade backstage's dependencies because they are way too far outdated and it resulted in CVE security issues.
The main issue causes CVE-2024-53983: Backstage Scaffolder plugin vulnerable to Server-Side Request Forgery
Without using @backstage/plugin-scaffolder-node <= 0.4.12 in your backend plugin it allows an attacker to capture privileged git tokens used by the Backstage Scaffolder plugin.