FreshRSS

๐Ÿ”’
โ˜ โ˜† โœ‡ Naked Security

Log4Shell-like code execution hole in popular Backstage dev tool

By Paul Ducklin โ€” November 15th 2022 at 17:49
Good old "string templating", also known as "string interpolation", in the spotlight again...

bs-1200

โ˜ โ˜† โœ‡ The Hacker News

Critical RCE Flaw Reported in Spotify's Backstage Software Catalog and Developer Platform

By Ravie Lakshmanan โ€” November 15th 2022 at 17:01
Spotify's Backstage has been discovered as vulnerable to a severe security flaw that could be exploited to gain remote code execution by leveraging a recently disclosed bug in a third-party module. The vulnerability (CVSS score: 9.8), at its core, takes advantage of a critical sandbox escape in vm2, a popular JavaScript sandbox library (CVE-2022-36067ย aka Sandbreak), that came to light last
โŒ