Scaffolder actions that interact with source control systems may not consistently enforce the intended credential boundaries under certain configurations. An authenticated user could perform operations with broader access than intended.
// patches- @backstage/plugin-scaffolder-backend version 4.1.0
- @backstage/plugin-scaffolder-backend-module-azure version 0.2.25
- @backstage/plugin-scaffolder-backend-module-bitbucket-cloud version 0.3.10
- @backstage/plugin-scaffolder-backend-module-bitbucket-server version 0.2.25
- @backstage/plugin-scaffolder-backend-module-github version 0.9.13
- @backstage/plugin-scaffolder-backend-module-gitlab version 0.11.10
The fix introduces a new configuration option that enforces user-provided credentials for supported SCM actions. The new behavior is opt-in for compatibility. After upgrading, set:
scaffolder: requireScmUserCredentials: true
Before enabling this setting, review and update your templates as described in the software templates documentation referred to below.
// workaroundsIf you cannot upgrade and enable the setting immediately:
- Restrict who can create Scaffolder tasks and which templates they can execute.
- Limit SCM integration credentials to the minimum repository read and mutation permissions required.
- Remove integration credentials for SCM hosts where all required operations can use explicitly supplied user tokens.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- Low
- User interaction
- None
- Scope
- Changed
- Confidentiality
- Low
- Integrity
- Low
- Availability
- None